SlideShare a Scribd company logo
EU General Data Protection Regulation after Brexit
EU GDPR post Brexit
John Culkin
Content
• Brexit and the General Data Protection Regulation (GDPR)
• What the GDPR says
• Immediate areas of focus & making the business case
• How information governance can help you
Brexit and the GDPR
• Approved by MEPs (Parliament) and Member States (Council)
after 4 years of negotiation
• Brexit doesn’t affect it
• It is the law now!
• Current ICO guidance being developed
Will become enforceable law in the UK & Ireland
(and member states) on the 24th May 2018
What the GDPR says
05
The new principles
The new principles are that information is:
01 04
02
0603
07
Processed fairly, lawfully
& in a transparent manner
Collected for specific, explicit
and legitimate purposes
Adequate, relevant and
limited to what is necessary to
meet the purpose
Accurate and up to date
Must not be kept for
longer than is necessary
Kept secure to maintain integrity
and confidentiality
Processed by controllers
and processors able to
demonstrate compliance
Name
and
contact
details
The
envisaged
time limits for
erasure data
Technical and
organisational
security
measures
Categories:
- Data subjects
- Personal data
Purposes
of
processes
To whom
personal
data was
disclosed
Transfers
of personal
data
Each controller must
maintain a record of
processing activities. That
record must contain the
following information:
Demonstrate compliance
GDPR Requirements
Governance
& policy
Data
inventory
Third
party
mgmt.
Information
security
Risk
mgmt.
Incident &
breach
management
Procedures
& controls
- Marketing & Data collection
(incl.Consent management)
- Complaints & Data Subject’s Rights
- Automated decision making & Risk
profiling
- Employment processing
Assurance
Fines
Inadequate processing of child data
Processing which does not require identification
Inadequate Data Protection by Design
Inadequate controller & processor management
Inadequate security controls
Non notification of breaches
Inadequate Data Protection Officer appointment
Breaches of Codes of Conduct and/or Certifications
Each supervisory authority shall have the power to issue
administrative fines of up to 10 million euros for breaches of;
Fines
Breaches of the basic principles for processing including conditions for consent
Inadequate compliance with Data Subject rights
Inappropriate transfers outside of the EEA
Breaches of relevant member state law
Non-compliance with an order from the Supervisory Authority
Each supervisory authority shall have the power to issue
administrative fines of up to 20 million euros for breaches of;
Good Information Governance could
save your skin!
It assists with compliance
requirements, making some
elements of the GDPR less
burdensome
additional efficiency benefits
to the organisation
By keeping accurate and robust
records on your processing
activities and controls you can
defend your position better with
a regulator or a data subject
It makes it easier to
risk manage your
estate & infrastructure
& investigate incidents
faster
Unknown unknowns…
• Equivalency not recognised or drift apart
• Maybe we want higher standards
• The Trump effect – US data transfers
• Privacy awareness impact
• Monetising data – my data my money
• Case law developments – permission previously given?
Immediate areas of focus
What you have
Where it is
Where you are
sending to
Why you have it
What form it is in
How long you need
to keep it
Ultimately you need
to know
How can you achieve this?
Understand what information
you have and what you need:
• Information lifecycle
• Information management
platform
• Policies and procedures
1. Begin with an information audit
2. Decide what data to keep
3. Securely destroy unnecessary data
10100010110101001011010100110101101000101101
01101000110101011011010110101001101010101000
10100010110101001011010100110101101000101101
00101000110101011011011010100110101010001010
10100010110110110101001101010100010110100101
00101000110101011011010100110101101000100001
4. Set a budget for a Data Protection
Officer and oversee the appointment
5. Begin staff training and review your
information governance framework
6. Put a clear and effective reporting
process in place for data breaches
7. Create a remediation
programme to deliver
compliance with GDPR
8. Create a business case for IG focusing on value
Don’t make the headlines:
Reputational damage is more expensive than fines
ARE THERE ANY
QUESTIONS
Thank you
For more information about GDPR please visit
www.crownrms.com/gdpr
Contact
+44 (0)20 8443 6016
sales.uk@crownrms.com
John Culkin – Director Information Management
jculkin@Crownww.com

More Related Content

What's hot

What's hot (20)

A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
12 steps to prepare for GDPR
12 steps to prepare for GDPR12 steps to prepare for GDPR
12 steps to prepare for GDPR
 
GDPR Readiness
GDPR ReadinessGDPR Readiness
GDPR Readiness
 
How does GDPR affect the design of user experiences?
How does GDPR affect the design of user experiences? How does GDPR affect the design of user experiences?
How does GDPR affect the design of user experiences?
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 
10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPR10 Good Reasons: NetApp for GDPR
10 Good Reasons: NetApp for GDPR
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
What does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businessesWhat does GDPR laws mean for Australian businesses
What does GDPR laws mean for Australian businesses
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
 
GDPR Privacy Policy
GDPR Privacy PolicyGDPR Privacy Policy
GDPR Privacy Policy
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 

Viewers also liked

Post Brexit EU and the position of English - Robert Phillipson
Post Brexit EU and the position of English - Robert PhillipsonPost Brexit EU and the position of English - Robert Phillipson
Post Brexit EU and the position of English - Robert Phillipson
rceluoa
 

Viewers also liked (19)

Microsoft Trusted Cloud - Harald Leitenmüller (Microsoft)
Microsoft Trusted Cloud - Harald Leitenmüller (Microsoft)Microsoft Trusted Cloud - Harald Leitenmüller (Microsoft)
Microsoft Trusted Cloud - Harald Leitenmüller (Microsoft)
 
The top 5 factors impacting third party risk management
The top 5 factors impacting third party risk managementThe top 5 factors impacting third party risk management
The top 5 factors impacting third party risk management
 
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
Nick Stringer - Five Key Things EU General Data Protection Regulation (GDPR) ...
 
Post Brexit EU and the position of English - Robert Phillipson
Post Brexit EU and the position of English - Robert PhillipsonPost Brexit EU and the position of English - Robert Phillipson
Post Brexit EU and the position of English - Robert Phillipson
 
Brexit what are the implications for eu based exporters to the uk
Brexit what are the implications for eu based exporters to the ukBrexit what are the implications for eu based exporters to the uk
Brexit what are the implications for eu based exporters to the uk
 
UK's Exit from the EU: BREXIT
UK's Exit from the EU: BREXITUK's Exit from the EU: BREXIT
UK's Exit from the EU: BREXIT
 
What does BREXIT mean for my EU funding? EU Environmental Funding Webinar
What does BREXIT mean for my EU funding? EU Environmental Funding Webinar What does BREXIT mean for my EU funding? EU Environmental Funding Webinar
What does BREXIT mean for my EU funding? EU Environmental Funding Webinar
 
BNC 2016 - Issue4: Brexit and the EU referendum
BNC 2016 - Issue4: Brexit and the EU referendumBNC 2016 - Issue4: Brexit and the EU referendum
BNC 2016 - Issue4: Brexit and the EU referendum
 
Office 365 security concerns, EU General Data Protection Regulation (GDPR)
Office 365 security concerns, EU General Data Protection Regulation (GDPR) Office 365 security concerns, EU General Data Protection Regulation (GDPR)
Office 365 security concerns, EU General Data Protection Regulation (GDPR)
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
Zachman Framework As Enterprise Architecture Ontology
Zachman Framework As Enterprise Architecture OntologyZachman Framework As Enterprise Architecture Ontology
Zachman Framework As Enterprise Architecture Ontology
 
EU Referendum: Brexit and the Implications for Brands
EU Referendum: Brexit and the Implications for BrandsEU Referendum: Brexit and the Implications for Brands
EU Referendum: Brexit and the Implications for Brands
 
Accenture Security Framework for AWS: Monetary Authority of Singapore Guidelines
Accenture Security Framework for AWS: Monetary Authority of Singapore GuidelinesAccenture Security Framework for AWS: Monetary Authority of Singapore Guidelines
Accenture Security Framework for AWS: Monetary Authority of Singapore Guidelines
 
الشعلة السابعة-..-حبينا-..1989
الشعلة السابعة-..-حبينا-..1989الشعلة السابعة-..-حبينا-..1989
الشعلة السابعة-..-حبينا-..1989
 
5 Apps That Help Us Give Back
5 Apps That Help Us Give Back 5 Apps That Help Us Give Back
5 Apps That Help Us Give Back
 
Winter Excitement In NYC
Winter Excitement In NYC Winter Excitement In NYC
Winter Excitement In NYC
 
Martin Heaven Taking HEED presentation at the launch of the Administrative Da...
Martin Heaven Taking HEED presentation at the launch of the Administrative Da...Martin Heaven Taking HEED presentation at the launch of the Administrative Da...
Martin Heaven Taking HEED presentation at the launch of the Administrative Da...
 
Prezentacja funduszu
Prezentacja funduszuPrezentacja funduszu
Prezentacja funduszu
 

Similar to CIO Summit talk: EU GDPR

The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
Rachel Aldighieri
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
Rachel Aldighieri
 
ISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptx
ISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptxISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptx
ISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptx
PECB
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
Rachel Aldighieri
 

Similar to CIO Summit talk: EU GDPR (20)

Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
[Webinar Slides] Think Brexit Saves You From EU Data Regulations? Think Again!
[Webinar Slides] Think Brexit Saves You From EU Data Regulations? Think Again![Webinar Slides] Think Brexit Saves You From EU Data Regulations? Think Again!
[Webinar Slides] Think Brexit Saves You From EU Data Regulations? Think Again!
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
GDPR webinar presentation | LawBite
GDPR webinar presentation | LawBiteGDPR webinar presentation | LawBite
GDPR webinar presentation | LawBite
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
DMA Scotland: Legal update
DMA Scotland: Legal updateDMA Scotland: Legal update
DMA Scotland: Legal update
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
GDPR training
GDPR training GDPR training
GDPR training
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
ISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptx
ISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptxISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptx
ISO-IEC 27701 and EU-U.S. Privacy Regulations What’s next.pptx
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
The GDPR Armageddon – One year on
The GDPR Armageddon – One year onThe GDPR Armageddon – One year on
The GDPR Armageddon – One year on
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 

Recently uploaded

Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
Bhaskar Mitra
 

Recently uploaded (20)

AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří Karpíšek
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptxWSO2CONMay2024OpenSourceConferenceDebrief.pptx
WSO2CONMay2024OpenSourceConferenceDebrief.pptx
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeFree and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
 
The architecture of Generative AI for enterprises.pdf
The architecture of Generative AI for enterprises.pdfThe architecture of Generative AI for enterprises.pdf
The architecture of Generative AI for enterprises.pdf
 
Agentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdfAgentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdf
 
"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi
 
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
SOQL 201 for Admins & Developers: Slice & Dice Your Org’s Data With Aggregate...
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 
PLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. StartupsPLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. Startups
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
 

CIO Summit talk: EU GDPR

  • 1. EU General Data Protection Regulation after Brexit EU GDPR post Brexit John Culkin
  • 2.
  • 3. Content • Brexit and the General Data Protection Regulation (GDPR) • What the GDPR says • Immediate areas of focus & making the business case • How information governance can help you
  • 4. Brexit and the GDPR • Approved by MEPs (Parliament) and Member States (Council) after 4 years of negotiation • Brexit doesn’t affect it • It is the law now! • Current ICO guidance being developed Will become enforceable law in the UK & Ireland (and member states) on the 24th May 2018
  • 6. 05 The new principles The new principles are that information is: 01 04 02 0603 07 Processed fairly, lawfully & in a transparent manner Collected for specific, explicit and legitimate purposes Adequate, relevant and limited to what is necessary to meet the purpose Accurate and up to date Must not be kept for longer than is necessary Kept secure to maintain integrity and confidentiality Processed by controllers and processors able to demonstrate compliance
  • 7. Name and contact details The envisaged time limits for erasure data Technical and organisational security measures Categories: - Data subjects - Personal data Purposes of processes To whom personal data was disclosed Transfers of personal data Each controller must maintain a record of processing activities. That record must contain the following information: Demonstrate compliance
  • 8. GDPR Requirements Governance & policy Data inventory Third party mgmt. Information security Risk mgmt. Incident & breach management Procedures & controls - Marketing & Data collection (incl.Consent management) - Complaints & Data Subject’s Rights - Automated decision making & Risk profiling - Employment processing Assurance
  • 9. Fines Inadequate processing of child data Processing which does not require identification Inadequate Data Protection by Design Inadequate controller & processor management Inadequate security controls Non notification of breaches Inadequate Data Protection Officer appointment Breaches of Codes of Conduct and/or Certifications Each supervisory authority shall have the power to issue administrative fines of up to 10 million euros for breaches of;
  • 10. Fines Breaches of the basic principles for processing including conditions for consent Inadequate compliance with Data Subject rights Inappropriate transfers outside of the EEA Breaches of relevant member state law Non-compliance with an order from the Supervisory Authority Each supervisory authority shall have the power to issue administrative fines of up to 20 million euros for breaches of;
  • 11. Good Information Governance could save your skin! It assists with compliance requirements, making some elements of the GDPR less burdensome additional efficiency benefits to the organisation By keeping accurate and robust records on your processing activities and controls you can defend your position better with a regulator or a data subject It makes it easier to risk manage your estate & infrastructure & investigate incidents faster
  • 12. Unknown unknowns… • Equivalency not recognised or drift apart • Maybe we want higher standards • The Trump effect – US data transfers • Privacy awareness impact • Monetising data – my data my money • Case law developments – permission previously given?
  • 13. Immediate areas of focus What you have Where it is Where you are sending to Why you have it What form it is in How long you need to keep it Ultimately you need to know
  • 14. How can you achieve this?
  • 15. Understand what information you have and what you need: • Information lifecycle • Information management platform • Policies and procedures 1. Begin with an information audit
  • 16. 2. Decide what data to keep
  • 17. 3. Securely destroy unnecessary data 10100010110101001011010100110101101000101101 01101000110101011011010110101001101010101000 10100010110101001011010100110101101000101101 00101000110101011011011010100110101010001010 10100010110110110101001101010100010110100101 00101000110101011011010100110101101000100001
  • 18. 4. Set a budget for a Data Protection Officer and oversee the appointment
  • 19. 5. Begin staff training and review your information governance framework
  • 20. 6. Put a clear and effective reporting process in place for data breaches
  • 21. 7. Create a remediation programme to deliver compliance with GDPR
  • 22. 8. Create a business case for IG focusing on value
  • 23. Don’t make the headlines: Reputational damage is more expensive than fines
  • 26. For more information about GDPR please visit www.crownrms.com/gdpr Contact +44 (0)20 8443 6016 sales.uk@crownrms.com John Culkin – Director Information Management jculkin@Crownww.com