SlideShare a Scribd company logo
Hans Demeyer
Supplier of Optimism & Inspiration
On GDPR
The General Data Protection Regulation
and how to maximize compliancy
• Post-world war II
• 1950 - European Declaration of Rights
• 1992 – Belgian law on personal privacy
• 1995 – European Privacy directives
• 2000-2010 – Telecommunications law, e-
commerce, additional Local directives, CLAs
• May 2016 – General Data Protection Regulation
• Grace period
• May 2018 – binding law
history
11
12
20
78
42
3
GDPR - content
General and principles
Data Subject rights
Controller responsibilities
Sending data outside the EU
Remedies
Administration
Security
Hans Demeyer
Supplier of Optimism & Inspiration
• Linkedin.com/in/hansdemeyer
• Hans@thedataprotectionoffice.eu
April 2015
“your aproach is disruptive and far better
then what the average SME delivers. Don’t
let that value get lost.”
“Finally a pragmatic and clear session on
GDPR. Thank you.”
“inspiring and ready to put into action”
“no fear, just optimism and concrete
action outlines”
B2B, B2C, Staff
What data?
Personal data (Active opt-in*)
- Name : Sophie D
- Address : street, N°,city, country
- Mail address : Sophie@Hotmail.com
- Photo
- Biometric info: fingerprints, face reco, …
- Ip-address, Mac-Address
- IQ info
- Profiling info
- Online behaviour
- Location data
- Aliases (twitter, FB, …)
- Combinations leading to potential
identification of a natural person
Sensitive data (Explicit consent)
- Sexual preferences
- Medical info
- Union choice
- Political, religious prefs
- Memberships
- National ID number
*Unless < 16
Company data, info@,
sales@, … are not GDPR
sensitive
Understanding the
impact
Data subjects
Controllers & Processors
The GDPR journey
Your
organisation
destination
Your mission
Your value prop
Value
proposition
ActivitiesPartners Customers
Cost Revenue
Resources
CRM
Channel
Marketing &
Sales
entry processing exit
Your
organisation
Your mission
Your value prop
marketing
destination
GDPR rights for citizens
How are you
processing my
data?
What personal
data do you
have?
Please correct
or add
incomplete
data
Please remove
my data
Please stop
using my data
for marketing
Opt me out for
1 specific part
of the
processing
Can I get a
copy of my
data?
I object to a
presumed
automated
decision
What do you
need my data
for?
How long do
you keep my
data
Where do you
store my
personal data?
Your
organisation
Privacy declaration
Cookies & trackers
• 1st party
• 3rd party
Only what is needed
Digital & Analogue
Your
organisation
Your mission
Your value prop
marketing
destination
Data processing – 6 grounds
1 CONSENT
• Communicated
upfront
• Clear
• Fragmented
• Recorded
• Procedure
• Motivated
• Relevant
2 CONTRACT
• All processing and
data transfert
required to fullfil
the agreement
• No additional
consent required
3 LAW
• All processing and
data transfert
required by law
• No additional
consent required
4 HEALTH
• All processing and
data transfert to
assure the health
of an individual or
group
• No additional
consent required
5 COMMON
INTEREST
• All processing and
data transfert to
assure the
common interest,
security, .. Of a
group
• No additional
consent required
6 LEGITIMATE CAUSE
• All processing and
data transfert
pondered and
motivated that
serves the
interests of the
subject and the
controller without
conflicts
When processing personal data, always
check if 1 of the 6 answers aside is
applicable
https://privacycommission.be/(nl-fr)
functionele omschrijving verwerking gebruikte gegevens en betrokkenen verwerker gegevensuitwisseling technologie risico & beveiligingsmaatregelen rechten betrokkenen status opmerking
identificatieen informatieover de verwerking
nummer, functionele omschrijving, finaliteit,
verwerkingsgrond, type verwerking en
functionelebeschrijving
details over de gegevens die verwerkt worden
en de betrokkenen van wie gegevens verwerkt
worden
functionelecategorie, gevoeligecategorie
gegevensverwerking, categoriebetrokken,
classificatieniveau, bewaartermijn, authentieke
bron
identificatievan de verwerker (extern aan
organisatie) die betrokken is bij de verwerking
naam, nr gegevensverwerkingscontract
informatieover eventuele gegevensuitwisseling
met derde partijen
categorie(ën)gegevens,categorie(ën)
ontvangers, derde land/internationale
organisatie, documenten passende waarborgen
beschrijving van de gebruikte technologie,
applicaties, software bij de verwerking
informatie over het risico en de
beveiligingsmaatregelen van de
gegevensverwerking
risico, beschrijving
beveiligingsmaatregelen, documentatie
beveiligingsmaatregelen, GEB (DPIA)
verwijzing naar de documenten die de
procedures ter respectering van de rechten van
de betrokkenen bepalen
informatieover de status van de verwerking: startdatum,
einddatum en plaatsvervangendeverwerking
noteer eventuele opmerkingen/aandachtspunten mbt de
verwerkingsactiviteit
Process
Purpose (why)
Data processed (what)
Retention (how long)
Data processor (who)
Legal ground
What technology is used?
What is the risk?
What rights could be exercised?
Status
Remarks
Be accountable – document your processes
News letter sharing
Send updates via newsletter
Name, mail address
till opt-out by customer
Marketing dpt
Consent (legitimate interest ?)
Mail chimp
low
Correct, get, opt-out, forget
Checking software & process
Ready for May 25
Job Applications & Staff
Existing
CLA’s
(61,81,82,89,…)
Check your
HR Agency
Add GDPR
‘NDA’ to
contract
GDPR processor
agreements
Your
organisation
Madrid
Your mission
Your value prop
marketing
What about security?
unlikely low medium high certain
Probability of leaks
negligableminimalsignificanthighcritical
Impactofleaks
• Respect for private and
family life, home and
communications
• Physical and mental
integrity
• Liberty and security
• Freedom of thought
• Data protection
• Freedom to work and
choose an occupation
« Risk assessment »
Incidents must be reported within 72hrs
On premise
Outside (! Outside Europe)
Fixed Mobile
Security = where, what, who, when, how?
List
- devices
- software
- apps
- other?
As you see
them inside the
company and
outside the
company both
fixed and
mobile
On premise
Outside
Fixed Mobile
prints
cupboard
Who?
How?
What?
High impact
Low impact
Easy Complex
Next move
citizen Mediator
Reconcile
complaint
YES
NO
chamber
Inspection
warn
fine
classify
appeal
court
complaint
GDPR - escalation
Your
organisation Madrid
Your mission
Your value prop
marketing
Steps toward GDPR compliancy for self-employed and Small & Medium size businesses
Thank you
http://Thedataprotectionoffice.eu
hans@thedataprotectionoffice.eu
Lees onze
welkomstbrochure
The Data Protection Office
Mosseveldstraat 34 a
9290 Overmere
+32 496 16 33 01
GDPR begeleiding voor
Zelfstandigen en KMO’s
Reserveer uw
begeleiding hier
The Data Protection Office is een handelsmerk van
CT-Interactive bvba – BE0462541827
A very clear gdpr story for normal people
A very clear gdpr story for normal people
A very clear gdpr story for normal people

More Related Content

What's hot

Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
Harrison Clark Rickerbys
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
Microsoft Österreich
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
Mailjet
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
HackerOne
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
Kwanzoo Inc
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
DATUM LLC
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
Promapp Solutions
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
Fionnuala Hendrick
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
HackerOne
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
Ulf Mattsson
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
Dr. Sami Zahran
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
DATUM LLC
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
Rachel Aldighieri
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
DAMA Ireland
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Jean-Michel Franco
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
Tim Gough
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
Hans Demeyer
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
Spain-Holiday.com
 

What's hot (20)

Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
Sophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPRSophie's Privacy - a story about GDPR
Sophie's Privacy - a story about GDPR
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 

Similar to A very clear gdpr story for normal people

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
CBC GDPR The Physics
CBC GDPR The PhysicsCBC GDPR The Physics
CBC GDPR The Physics
Jason Chapman
 
DPA seminar presentation
DPA seminar presentationDPA seminar presentation
DPA seminar presentation
Rodonoghue72
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
One North
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
Andreas Batsis
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Richard Veryard
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
Louise Owens
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance
Gabor Farkas
 
Are you GDPR compliant?
Are you GDPR compliant? Are you GDPR compliant?
Are you GDPR compliant?
TrekkSoft
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
BrightPay Payroll and Auto Enrolment Software
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
TimBee1
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
TimBee1
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
Human Capital Department
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliant
Esendex
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
ObservePoint
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
Tech Trust
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Bart Van Den Brande
 
2018 Client Briefing GDPR
2018 Client Briefing GDPR2018 Client Briefing GDPR
2018 Client Briefing GDPR
Carsted Rosenberg Advokatfirma
 
CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticheramy_hatton
 

Similar to A very clear gdpr story for normal people (20)

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
CBC GDPR The Physics
CBC GDPR The PhysicsCBC GDPR The Physics
CBC GDPR The Physics
 
DPA seminar presentation
DPA seminar presentationDPA seminar presentation
DPA seminar presentation
 
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
#1NWebinar: GDPR and Privacy Best Practices for Digital Marketers
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
 
How will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett LongHow will GDPR affect your business - Marketing Fox & Birkett Long
How will GDPR affect your business - Marketing Fox & Birkett Long
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance
 
Are you GDPR compliant?
Are you GDPR compliant? Are you GDPR compliant?
Are you GDPR compliant?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
SMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliantSMS and GDPR - what you need to know to be compliant
SMS and GDPR - what you need to know to be compliant
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
 
2018 Client Briefing GDPR
2018 Client Briefing GDPR2018 Client Briefing GDPR
2018 Client Briefing GDPR
 
CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticher
 

More from Hans Demeyer

Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Shiny goals keynote (1hr)
Shiny goals keynote (1hr)
Hans Demeyer
 
Discovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainDiscovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brain
Hans Demeyer
 
De verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinDe verborgen schat van het piratenbrein
De verborgen schat van het piratenbrein
Hans Demeyer
 
Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?
Hans Demeyer
 
Je brein houdt je voor de gek
Je brein houdt je voor de gekJe brein houdt je voor de gek
Je brein houdt je voor de gek
Hans Demeyer
 
Infographic - gdpr and smb
Infographic -  gdpr and smbInfographic -  gdpr and smb
Infographic - gdpr and smb
Hans Demeyer
 
Speed dating with GDPR
Speed dating with GDPRSpeed dating with GDPR
Speed dating with GDPR
Hans Demeyer
 
Communicate effectively
Communicate effectivelyCommunicate effectively
Communicate effectively
Hans Demeyer
 
Sustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologySustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable Technology
Hans Demeyer
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
Hans Demeyer
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
Hans Demeyer
 
Stuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProStuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales Pro
Hans Demeyer
 
Challenger sales
Challenger salesChallenger sales
Challenger sales
Hans Demeyer
 
Vox entrepreneurs_nl
Vox entrepreneurs_nlVox entrepreneurs_nl
Vox entrepreneurs_nl
Hans Demeyer
 
Meer verkopen, minder babbelen
Meer verkopen, minder babbelenMeer verkopen, minder babbelen
Meer verkopen, minder babbelen
Hans Demeyer
 
From Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessFrom Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying Process
Hans Demeyer
 
Sales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourSales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch Tour
Hans Demeyer
 
Sales training (focus on telesales)
Sales training (focus on telesales)Sales training (focus on telesales)
Sales training (focus on telesales)
Hans Demeyer
 
Public speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audiencePublic speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audience
Hans Demeyer
 

More from Hans Demeyer (20)

Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Shiny goals keynote (1hr)
Shiny goals keynote (1hr)
 
Discovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainDiscovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brain
 
De verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinDe verborgen schat van het piratenbrein
De verborgen schat van het piratenbrein
 
Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?
 
Je brein houdt je voor de gek
Je brein houdt je voor de gekJe brein houdt je voor de gek
Je brein houdt je voor de gek
 
Infographic - gdpr and smb
Infographic -  gdpr and smbInfographic -  gdpr and smb
Infographic - gdpr and smb
 
Speed dating with GDPR
Speed dating with GDPRSpeed dating with GDPR
Speed dating with GDPR
 
Communicate effectively
Communicate effectivelyCommunicate effectively
Communicate effectively
 
Sustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologySustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable Technology
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
 
Stuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProStuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales Pro
 
Challenger sales
Challenger salesChallenger sales
Challenger sales
 
Happiness
HappinessHappiness
Happiness
 
Vox entrepreneurs_nl
Vox entrepreneurs_nlVox entrepreneurs_nl
Vox entrepreneurs_nl
 
Meer verkopen, minder babbelen
Meer verkopen, minder babbelenMeer verkopen, minder babbelen
Meer verkopen, minder babbelen
 
From Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessFrom Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying Process
 
Sales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourSales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch Tour
 
Sales training (focus on telesales)
Sales training (focus on telesales)Sales training (focus on telesales)
Sales training (focus on telesales)
 
Public speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audiencePublic speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audience
 

Recently uploaded

Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
Cynthia Clay
 
April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
NathanBaughman3
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
Nicola Wreford-Howard
 
Global Interconnection Group Joint Venture[960] (1).pdf
Global Interconnection Group Joint Venture[960] (1).pdfGlobal Interconnection Group Joint Venture[960] (1).pdf
Global Interconnection Group Joint Venture[960] (1).pdf
Henry Tapper
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
BBPMedia1
 
chapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxationchapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxation
AUDIJEAngelo
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
Sam H
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
Operational Excellence Consulting
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
Ben Wann
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
dylandmeas
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
Workforce Group
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Arihant Webtech Pvt. Ltd
 
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deckPitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
HajeJanKamps
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
zoyaansari11365
 
What is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdfWhat is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdf
seoforlegalpillers
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
BBPMedia1
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
usawebmarket
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
Falcon Invoice Discounting
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
anasabutalha2013
 
What are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdfWhat are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdf
HumanResourceDimensi1
 

Recently uploaded (20)

Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
 
Global Interconnection Group Joint Venture[960] (1).pdf
Global Interconnection Group Joint Venture[960] (1).pdfGlobal Interconnection Group Joint Venture[960] (1).pdf
Global Interconnection Group Joint Venture[960] (1).pdf
 
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
RMD24 | Retail media: hoe zet je dit in als je geen AH of Unilever bent? Heid...
 
chapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxationchapter 10 - excise tax of transfer and business taxation
chapter 10 - excise tax of transfer and business taxation
 
Unveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdfUnveiling the Secrets How Does Generative AI Work.pdf
Unveiling the Secrets How Does Generative AI Work.pdf
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
 
Improving profitability for small business
Improving profitability for small businessImproving profitability for small business
Improving profitability for small business
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
 
Cracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptxCracking the Workplace Discipline Code Main.pptx
Cracking the Workplace Discipline Code Main.pptx
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
 
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deckPitch Deck Teardown: RAW Dating App's $3M Angel deck
Pitch Deck Teardown: RAW Dating App's $3M Angel deck
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
 
What is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdfWhat is the TDS Return Filing Due Date for FY 2024-25.pdf
What is the TDS Return Filing Due Date for FY 2024-25.pdf
 
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
RMD24 | Debunking the non-endemic revenue myth Marvin Vacquier Droop | First ...
 
Buy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star ReviewsBuy Verified PayPal Account | Buy Google 5 Star Reviews
Buy Verified PayPal Account | Buy Google 5 Star Reviews
 
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-indiafalcon-invoice-discounting-a-premier-platform-for-investors-in-india
falcon-invoice-discounting-a-premier-platform-for-investors-in-india
 
anas about venice for grade 6f about venice
anas about venice for grade 6f about veniceanas about venice for grade 6f about venice
anas about venice for grade 6f about venice
 
What are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdfWhat are the main advantages of using HR recruiter services.pdf
What are the main advantages of using HR recruiter services.pdf
 

A very clear gdpr story for normal people

  • 1. Hans Demeyer Supplier of Optimism & Inspiration On GDPR The General Data Protection Regulation and how to maximize compliancy
  • 2. • Post-world war II • 1950 - European Declaration of Rights • 1992 – Belgian law on personal privacy • 1995 – European Privacy directives • 2000-2010 – Telecommunications law, e- commerce, additional Local directives, CLAs • May 2016 – General Data Protection Regulation • Grace period • May 2018 – binding law history
  • 3. 11 12 20 78 42 3 GDPR - content General and principles Data Subject rights Controller responsibilities Sending data outside the EU Remedies Administration Security
  • 4.
  • 5.
  • 6. Hans Demeyer Supplier of Optimism & Inspiration • Linkedin.com/in/hansdemeyer • Hans@thedataprotectionoffice.eu
  • 8. “your aproach is disruptive and far better then what the average SME delivers. Don’t let that value get lost.” “Finally a pragmatic and clear session on GDPR. Thank you.” “inspiring and ready to put into action” “no fear, just optimism and concrete action outlines”
  • 9.
  • 11. What data? Personal data (Active opt-in*) - Name : Sophie D - Address : street, N°,city, country - Mail address : Sophie@Hotmail.com - Photo - Biometric info: fingerprints, face reco, … - Ip-address, Mac-Address - IQ info - Profiling info - Online behaviour - Location data - Aliases (twitter, FB, …) - Combinations leading to potential identification of a natural person Sensitive data (Explicit consent) - Sexual preferences - Medical info - Union choice - Political, religious prefs - Memberships - National ID number *Unless < 16 Company data, info@, sales@, … are not GDPR sensitive
  • 13. Data subjects Controllers & Processors The GDPR journey
  • 16. Your organisation Your mission Your value prop marketing destination
  • 17. GDPR rights for citizens How are you processing my data? What personal data do you have? Please correct or add incomplete data Please remove my data Please stop using my data for marketing Opt me out for 1 specific part of the processing Can I get a copy of my data? I object to a presumed automated decision What do you need my data for? How long do you keep my data Where do you store my personal data? Your organisation
  • 19. Cookies & trackers • 1st party • 3rd party
  • 20. Only what is needed
  • 22. Your organisation Your mission Your value prop marketing destination
  • 23. Data processing – 6 grounds 1 CONSENT • Communicated upfront • Clear • Fragmented • Recorded • Procedure • Motivated • Relevant 2 CONTRACT • All processing and data transfert required to fullfil the agreement • No additional consent required 3 LAW • All processing and data transfert required by law • No additional consent required 4 HEALTH • All processing and data transfert to assure the health of an individual or group • No additional consent required 5 COMMON INTEREST • All processing and data transfert to assure the common interest, security, .. Of a group • No additional consent required 6 LEGITIMATE CAUSE • All processing and data transfert pondered and motivated that serves the interests of the subject and the controller without conflicts When processing personal data, always check if 1 of the 6 answers aside is applicable
  • 25. functionele omschrijving verwerking gebruikte gegevens en betrokkenen verwerker gegevensuitwisseling technologie risico & beveiligingsmaatregelen rechten betrokkenen status opmerking identificatieen informatieover de verwerking nummer, functionele omschrijving, finaliteit, verwerkingsgrond, type verwerking en functionelebeschrijving details over de gegevens die verwerkt worden en de betrokkenen van wie gegevens verwerkt worden functionelecategorie, gevoeligecategorie gegevensverwerking, categoriebetrokken, classificatieniveau, bewaartermijn, authentieke bron identificatievan de verwerker (extern aan organisatie) die betrokken is bij de verwerking naam, nr gegevensverwerkingscontract informatieover eventuele gegevensuitwisseling met derde partijen categorie(ën)gegevens,categorie(ën) ontvangers, derde land/internationale organisatie, documenten passende waarborgen beschrijving van de gebruikte technologie, applicaties, software bij de verwerking informatie over het risico en de beveiligingsmaatregelen van de gegevensverwerking risico, beschrijving beveiligingsmaatregelen, documentatie beveiligingsmaatregelen, GEB (DPIA) verwijzing naar de documenten die de procedures ter respectering van de rechten van de betrokkenen bepalen informatieover de status van de verwerking: startdatum, einddatum en plaatsvervangendeverwerking noteer eventuele opmerkingen/aandachtspunten mbt de verwerkingsactiviteit Process Purpose (why) Data processed (what) Retention (how long) Data processor (who) Legal ground What technology is used? What is the risk? What rights could be exercised? Status Remarks Be accountable – document your processes News letter sharing Send updates via newsletter Name, mail address till opt-out by customer Marketing dpt Consent (legitimate interest ?) Mail chimp low Correct, get, opt-out, forget Checking software & process Ready for May 25
  • 26. Job Applications & Staff Existing CLA’s (61,81,82,89,…) Check your HR Agency Add GDPR ‘NDA’ to contract
  • 28. Your organisation Madrid Your mission Your value prop marketing What about security?
  • 29. unlikely low medium high certain Probability of leaks negligableminimalsignificanthighcritical Impactofleaks • Respect for private and family life, home and communications • Physical and mental integrity • Liberty and security • Freedom of thought • Data protection • Freedom to work and choose an occupation « Risk assessment » Incidents must be reported within 72hrs
  • 30. On premise Outside (! Outside Europe) Fixed Mobile Security = where, what, who, when, how? List - devices - software - apps - other? As you see them inside the company and outside the company both fixed and mobile
  • 32. High impact Low impact Easy Complex Next move
  • 34. Your organisation Madrid Your mission Your value prop marketing Steps toward GDPR compliancy for self-employed and Small & Medium size businesses
  • 35. Thank you http://Thedataprotectionoffice.eu hans@thedataprotectionoffice.eu Lees onze welkomstbrochure The Data Protection Office Mosseveldstraat 34 a 9290 Overmere +32 496 16 33 01 GDPR begeleiding voor Zelfstandigen en KMO’s Reserveer uw begeleiding hier The Data Protection Office is een handelsmerk van CT-Interactive bvba – BE0462541827