SlideShare a Scribd company logo
1 of 4
Do You Have a Roadmap for EU GDPR Compliance?
By Ulf Mattssonat AtlanticBT, KhizarA.SheikhatMandelbaumSalsburg, andIanWest,Specialistin
GDPR.
GDPR is Top Priority in US
Overhalf of US multinationalssayGDPRistheirtop data- protectionpriority accordingtoPWC.Of the
200 respondents, 54% reportedthatGDPR readinessisthe highestpriorityontheirdata-privacyand
securityagenda.Another38%saidGDPR is one of several toppriorities,while only7% saiditisn’ta top
priority.
General Background
The EU General Data ProtectionRegulation(GDPR) wasadoptedonApril 8,2016 and will take effecton
May 25, 2018. The GDPR will replace the currentthe currentData ProtectionDirective 95/46/ECand will
be directlyapplicableinall MemberStateswithoutthe needforimplementingnational legislation.The
Article 29 WorkingParty (WP29) firstguidelinesondataprotectionofficers,one-stop- shop,andthe
newrightto data portabilitywere adoptedonApril 5,2017, andmore guidelinesare expected.
Part of the GDPR Rulesis Already a Reality
Some examples:Partof the proposed GDPR data protectionrulesare already implementedby
organzationsacross EU, includingGermanyandItalyforpersonal financial data.Germanoutsourcing
companiesare will be used.enforcingstrictrulesfordataprotection.DataprotectionrulesinSweden
are now basedon howthe data is used.
GDPR Expanded Territorial Reach
The GDPR Ruleswill have the followingimpactaccordingtoKhizarA. Sheikh,Chair,Privacy,
Cybersecurity,andDataLaw,MandelbaumSalsburg,UnitedStates,ksheikh@lawfirm.ms:
The GDPR regulatesdatacontrollersandprocessorsoutside the EUwhose processingactivitiesrelate to
the offeringof goodsor services(evenif forfree) to,ormonitoringthe behaviorof,datasubjectsinthe
EU. “Offeringgoodsorservices”ismore thanmere accessto a website oremail address,butcouldbe
triggeredbyuse of language or currencygenerallyusedinone ormore MemberStateswiththe
possibilityof orderinggoods/servicesthere and/ormentioningcustomersoruserswhoare in EU.
“Monitoringof behavior”will occur,e.g.,where individualsare trackedonthe internetbytechniques
whichapplya profile toenable decisionstobe made/predictpersonal preferences,etc. Thismeansthat
a companyoutside the EU whichis targetingconsumersinthe EU will be subjecttothe GDPR.
Role of Data Processors
Data processorshave directobligationsforthe firsttime.Theseinclude anobligationto: maintaina
writtenrecordof processingactivitiescarriedout onbehalf of eachcontroller; designate adata
protectionofficerwhererequired; appointarepresentative(whennotestablishedinthe EU) in certain
circumstances;and notifythe controlleronbecomingaware of apersonal databreach withoutundue
delay. Provisionsoncrossbordertransfersalsoapplytoprocessors,andBindingCorporate Rulesfor
processorsare formallyrecognized. New statusof dataprocessorswill impacthow dataprotection
mattersare addressedinsupplyandothercommercial agreements.
Notice / Consent
Data controllersmustcontinue toprovide transparentinformationtodatasubjectsatthe time personal
data isobtained. Existingformsof fairprocessingnoticesandconsentswill have tobe re-examinedas
GDPR requirementsare more detailed. Consentmustbe freelygiven,specific,informed,and
unambiguous,andmustbe as easyto withdraw asto give. Consentisnot freelygivenif the datasubject
has no genuine andfree choice orisunable towithdraw orrefuse consentwithoutdetriment. Consent
mustbe “explicit”forsensitive data. The datacontrollerisrequiredtobe able todemonstrate that
consentwasgiven.
Notice / Consent Issues
Contracts
Requestsforconsentshouldbe separate fromotherterms,andbe inclearand plainlanguage.Does
consentprovidesavalidlegal groundforprocessingwherethere isasignificantimbalance betweenthe
data subjectanddata controller? Whetherconsenthasbeenfreelygivendependson,e.g.,whetherthe
performance of a contract ismade conditional onthe consenttoprocessingdatathat isnot necessaryto
performthatcontract (mayaffecte-commerce services,amongothers).
Employment
MemberStatesmay provide more specificrulesforuse of consentinemploymentcontext.
Marketing
Where personal dataisprocessedfordirectmarketingthe datasubject will have arightto object. This
rightmust be explicitlybroughttotheirattention.
Children/ Parents
MemberStatescan lowerthe age from whomdata can be collectedfrom16 to 13 (lackof
harmonization).
Data Transformation
Whenis data nolongerthe data subjects’personal information?
Penalties
The GDPR establishesatieredapproach topenalties.Enablesthe DPAstoimpose finesforsome
breachesof the greaterof 4% of annual worldwide revenuesor20 millioneuros(e.g.,breachof
requirementsrelatingtointernational transfersorthe basicprinciplesforprocessing,suchasconditions
for consent). Otherspecifiedbreacheswouldbe subjecttoa fine of the greaterof 2% of annual
worldwide revenuesor10 millioneuros. A listof considerationswhenimposingfines(suchasthe
nature,gravityanddurationof the breach) isavailable.
Which Authority?
The mechanismiscomplicatedasitdistinguishesbetweencross-borderanddomesticprocessing. There
are complex cooperationandcoordinationproceduresforDPAs.Tohave theircasesdealtwithlocally,
the GDPR containsa detailedregime withaLeadAuthorityandConcernedSupervisoryAuthorities
workingtogether.The WP29** has providedguidance onhow toidentify aLeadSupervisoryAuthority.
It remainstobe seenhowitwill workinpractice andwhetheritcan workwithoutforumshopping.
GDPR = ENTERPRISEwide Trust
The GDPR Ruleswill have the followingimpactaccordingtoThe GDPR Institute*and IanWest,Specialist
inGDPR, Data Governance,DataPrivacy& Security,UnitedKingdom,ianwest348@gmail.com:
Impact
Do youcontrol or processpersonal dataaboutANY EU Citizens?If soyouhave to be GDPR compliantby
25th May 2018 or manage the implicationsof the finesandthe reputationaldamage of anyandevery
Data Breach – includingCustomersEmployeesSuppliers
Opportunity or Challenge?
Fines,Lossof Customers, Reputational Damage,andCOSTof Compliance are keyaspectsof GDPR. GDPR
involves EnterprisewideChange Management,PostRoom,andBoardRoom. It involves People,Process,
Technology,andInformation.
Key Questions
What Personal Datado youhold – Customer,Employee,Supplier,Contractor,Sub-Contractor,Citizen,
Patientetc. Where isthat Data Located?PC hard drive,Remote Storage orBackupDevice,OnPremise
Database or ContentServer,orinThe Cloud. How are youusingthat Data? Do youhave Explicitor
ImpliedPermissiontouse the datain the wayyou are usingit?
Immediate ActionPlan
SeekLegal Advice.ConductaPrivacyImpactAssessment.Complete aReadinessAssessmenttoaddress
the keyquestions.Secure Executive Sponsorshipanda meaningful budget.DevelopaConsent
ManagementStrategy. BuildaData SubjectAccessRequestprocessbeforeyougetswamped. Ensure
youhave all your Breach Detectiontechnologyinplace –Database,ContentRepositories,Network
Traffic,Dark Web8. Prepare forthe worst,and breathe a sigh of relief if itdoesn’thappen. The GDPR
Institute HelpingyouresolveYOURGDPR Challenge &Maximise the GDPROpportunity.
US businesses are re-evaluating their presenceinEurope
The PWC GDPR Survey foundthatUS corporationsthatare heavilyinvestedinEurope will probablystay
the course in the nearterm. Indeed,64% of executivesreportedthattheirtopstrategyforreducing
GDPR exposure iscentralizationof datacentersinEurope.Justoverhalf (54%) saidtheyplanto de-
identifyEuropeanpersonal datatoreduce exposure.The threatsof highfinesandimpactful injunctions,
however,clearlyhave manyothersreconsideringthe importance of the Europeanmarket.Infact,32%
of respondentsplantoreduce theirpresence inEurope,while26% intendtoexitthe EU market
altogether.
Companies are Spending millions to address GDPR
77% planto spend$1 millionormore on GDPR accordingto PWC.Securinga $1 millionbudgetfordata
privacyhas beenmore anexceptionthanarule for manyAmericancorporations.The GDPR’spotential
4% fine of global revenues,however,haschangedbudgetappetitesformitigatingthisGDPRrisk.While
24% of respondentsplantospendunder$1 millionforGDPRpreparations,68% saidtheywill invest
between$1millionand$10 million.Ninepercent(9%) expecttospendover$10 milliontoaddress
GDPR obligations.
More Learning
Webcastabout GDPR
Viewthis webinartolearnmore aboutthistopic at
https://www.brighttalk.com/webcast/14723/259741
More reading
*: AboutThe GDPR Institute,www.gdpr.institute . The GDPR Institute isaMembersOwnedNot-for-
ProfitOrganisation. The Institutes’Purpose Createacommunityof Data Privacy,DataSecurityand Data
Governance expertstoassistLarge,MediumandSmall Organisationsaddressthe challenge and
maximise the opportunitycreatedbythe General DataProtectionRegulationGDPRChallengeOrGDPR
Opportunity.
**: WP29: https://iapp.org/news/a/wp29-releases-extensive-employee-privacy-guidance/
AboutAtlanticBT: We deliverabalancedapproachto security,
https://www.atlanticbt.com/services/cybersecurity/

More Related Content

What's hot

Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non expertsClaudio Bolla, CISM
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsUlf Mattsson
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsUlf Mattsson
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR ComplianceDATAVERSITY
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPRJessvin Thomas
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
GDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projectsGDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projectsLorenzo Mannella
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 

What's hot (20)

Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
GDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projectsGDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projects
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 

Similar to Do You Have a Roadmap for EU GDPR Compliance? Article

What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow MappingVISTA InfoSec
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Gerson Trigueiros
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceObservePoint
 
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...Giulio Coraggio
 
GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadVisitor Analytics
 
Keep Calm and GDPR
Keep Calm and GDPRKeep Calm and GDPR
Keep Calm and GDPRMissMarvel70
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018Shane Gray
 
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...ARMA International
 
GDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratgGDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratgCyber StratG
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRRichard Veryard
 
Security, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightSecurity, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightN-iX
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the Newaccenture
 
How will GDPR affect small businesses?
How will GDPR affect small businesses?How will GDPR affect small businesses?
How will GDPR affect small businesses?AllBusinessTemplates
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 

Similar to Do You Have a Roadmap for EU GDPR Compliance? Article (20)

What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow Mapping
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
#Privacy Matters - Come il regolamento privacy europeo da un problema può div...
 
GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free Download
 
Keep Calm and GDPR
Keep Calm and GDPRKeep Calm and GDPR
Keep Calm and GDPR
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018
 
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
 
GDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratgGDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratg
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
 
Security, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightSecurity, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it right
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
 
How will GDPR affect small businesses?
How will GDPR affect small businesses?How will GDPR affect small businesses?
How will GDPR affect small businesses?
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 

More from Ulf Mattsson

Jun 29 new privacy technologies for unicode and international data standards ...
Jun 29 new privacy technologies for unicode and international data standards ...Jun 29 new privacy technologies for unicode and international data standards ...
Jun 29 new privacy technologies for unicode and international data standards ...Ulf Mattsson
 
Jun 15 privacy in the cloud at financial institutions at the object managemen...
Jun 15 privacy in the cloud at financial institutions at the object managemen...Jun 15 privacy in the cloud at financial institutions at the object managemen...
Jun 15 privacy in the cloud at financial institutions at the object managemen...Ulf Mattsson
 
May 6 evolving international privacy regulations and cross border data tran...
May 6   evolving international privacy regulations and cross border data tran...May 6   evolving international privacy regulations and cross border data tran...
May 6 evolving international privacy regulations and cross border data tran...Ulf Mattsson
 
Qubit conference-new-york-2021
Qubit conference-new-york-2021Qubit conference-new-york-2021
Qubit conference-new-york-2021Ulf Mattsson
 
Secure analytics and machine learning in cloud use cases
Secure analytics and machine learning in cloud use casesSecure analytics and machine learning in cloud use cases
Secure analytics and machine learning in cloud use casesUlf Mattsson
 
Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Ulf Mattsson
 
Data encryption and tokenization for international unicode
Data encryption and tokenization for international unicodeData encryption and tokenization for international unicode
Data encryption and tokenization for international unicodeUlf Mattsson
 
The future of data security and blockchain
The future of data security and blockchainThe future of data security and blockchain
The future of data security and blockchainUlf Mattsson
 
New technologies for data protection
New technologies for data protectionNew technologies for data protection
New technologies for data protectionUlf Mattsson
 
Privacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA AtlantaPrivacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA AtlantaUlf Mattsson
 
Safeguarding customer and financial data in analytics and machine learning
Safeguarding customer and financial data in analytics and machine learningSafeguarding customer and financial data in analytics and machine learning
Safeguarding customer and financial data in analytics and machine learningUlf Mattsson
 
Protecting data privacy in analytics and machine learning ISACA London UK
Protecting data privacy in analytics and machine learning ISACA London UKProtecting data privacy in analytics and machine learning ISACA London UK
Protecting data privacy in analytics and machine learning ISACA London UKUlf Mattsson
 
What is tokenization in blockchain - BCS London
What is tokenization in blockchain - BCS LondonWhat is tokenization in blockchain - BCS London
What is tokenization in blockchain - BCS LondonUlf Mattsson
 
Protecting data privacy in analytics and machine learning - ISACA
Protecting data privacy in analytics and machine learning - ISACAProtecting data privacy in analytics and machine learning - ISACA
Protecting data privacy in analytics and machine learning - ISACAUlf Mattsson
 
What is tokenization in blockchain?
What is tokenization in blockchain?What is tokenization in blockchain?
What is tokenization in blockchain?Ulf Mattsson
 
Nov 2 security for blockchain and analytics ulf mattsson 2020 nov 2b
Nov 2 security for blockchain and analytics   ulf mattsson 2020 nov 2bNov 2 security for blockchain and analytics   ulf mattsson 2020 nov 2b
Nov 2 security for blockchain and analytics ulf mattsson 2020 nov 2bUlf Mattsson
 
Unlock the potential of data security 2020
Unlock the potential of data security 2020Unlock the potential of data security 2020
Unlock the potential of data security 2020Ulf Mattsson
 
What is tokenization in blockchain?
What is tokenization in blockchain?What is tokenization in blockchain?
What is tokenization in blockchain?Ulf Mattsson
 
Protecting Data Privacy in Analytics and Machine Learning
Protecting Data Privacy in Analytics and Machine LearningProtecting Data Privacy in Analytics and Machine Learning
Protecting Data Privacy in Analytics and Machine LearningUlf Mattsson
 

More from Ulf Mattsson (20)

Jun 29 new privacy technologies for unicode and international data standards ...
Jun 29 new privacy technologies for unicode and international data standards ...Jun 29 new privacy technologies for unicode and international data standards ...
Jun 29 new privacy technologies for unicode and international data standards ...
 
Jun 15 privacy in the cloud at financial institutions at the object managemen...
Jun 15 privacy in the cloud at financial institutions at the object managemen...Jun 15 privacy in the cloud at financial institutions at the object managemen...
Jun 15 privacy in the cloud at financial institutions at the object managemen...
 
Book
BookBook
Book
 
May 6 evolving international privacy regulations and cross border data tran...
May 6   evolving international privacy regulations and cross border data tran...May 6   evolving international privacy regulations and cross border data tran...
May 6 evolving international privacy regulations and cross border data tran...
 
Qubit conference-new-york-2021
Qubit conference-new-york-2021Qubit conference-new-york-2021
Qubit conference-new-york-2021
 
Secure analytics and machine learning in cloud use cases
Secure analytics and machine learning in cloud use casesSecure analytics and machine learning in cloud use cases
Secure analytics and machine learning in cloud use cases
 
Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...
 
Data encryption and tokenization for international unicode
Data encryption and tokenization for international unicodeData encryption and tokenization for international unicode
Data encryption and tokenization for international unicode
 
The future of data security and blockchain
The future of data security and blockchainThe future of data security and blockchain
The future of data security and blockchain
 
New technologies for data protection
New technologies for data protectionNew technologies for data protection
New technologies for data protection
 
Privacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA AtlantaPrivacy preserving computing and secure multi-party computation ISACA Atlanta
Privacy preserving computing and secure multi-party computation ISACA Atlanta
 
Safeguarding customer and financial data in analytics and machine learning
Safeguarding customer and financial data in analytics and machine learningSafeguarding customer and financial data in analytics and machine learning
Safeguarding customer and financial data in analytics and machine learning
 
Protecting data privacy in analytics and machine learning ISACA London UK
Protecting data privacy in analytics and machine learning ISACA London UKProtecting data privacy in analytics and machine learning ISACA London UK
Protecting data privacy in analytics and machine learning ISACA London UK
 
What is tokenization in blockchain - BCS London
What is tokenization in blockchain - BCS LondonWhat is tokenization in blockchain - BCS London
What is tokenization in blockchain - BCS London
 
Protecting data privacy in analytics and machine learning - ISACA
Protecting data privacy in analytics and machine learning - ISACAProtecting data privacy in analytics and machine learning - ISACA
Protecting data privacy in analytics and machine learning - ISACA
 
What is tokenization in blockchain?
What is tokenization in blockchain?What is tokenization in blockchain?
What is tokenization in blockchain?
 
Nov 2 security for blockchain and analytics ulf mattsson 2020 nov 2b
Nov 2 security for blockchain and analytics   ulf mattsson 2020 nov 2bNov 2 security for blockchain and analytics   ulf mattsson 2020 nov 2b
Nov 2 security for blockchain and analytics ulf mattsson 2020 nov 2b
 
Unlock the potential of data security 2020
Unlock the potential of data security 2020Unlock the potential of data security 2020
Unlock the potential of data security 2020
 
What is tokenization in blockchain?
What is tokenization in blockchain?What is tokenization in blockchain?
What is tokenization in blockchain?
 
Protecting Data Privacy in Analytics and Machine Learning
Protecting Data Privacy in Analytics and Machine LearningProtecting Data Privacy in Analytics and Machine Learning
Protecting Data Privacy in Analytics and Machine Learning
 

Recently uploaded

My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?XfilesPro
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 

Recently uploaded (20)

My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 

Do You Have a Roadmap for EU GDPR Compliance? Article

  • 1. Do You Have a Roadmap for EU GDPR Compliance? By Ulf Mattssonat AtlanticBT, KhizarA.SheikhatMandelbaumSalsburg, andIanWest,Specialistin GDPR. GDPR is Top Priority in US Overhalf of US multinationalssayGDPRistheirtop data- protectionpriority accordingtoPWC.Of the 200 respondents, 54% reportedthatGDPR readinessisthe highestpriorityontheirdata-privacyand securityagenda.Another38%saidGDPR is one of several toppriorities,while only7% saiditisn’ta top priority. General Background The EU General Data ProtectionRegulation(GDPR) wasadoptedonApril 8,2016 and will take effecton May 25, 2018. The GDPR will replace the currentthe currentData ProtectionDirective 95/46/ECand will be directlyapplicableinall MemberStateswithoutthe needforimplementingnational legislation.The Article 29 WorkingParty (WP29) firstguidelinesondataprotectionofficers,one-stop- shop,andthe newrightto data portabilitywere adoptedonApril 5,2017, andmore guidelinesare expected. Part of the GDPR Rulesis Already a Reality Some examples:Partof the proposed GDPR data protectionrulesare already implementedby organzationsacross EU, includingGermanyandItalyforpersonal financial data.Germanoutsourcing companiesare will be used.enforcingstrictrulesfordataprotection.DataprotectionrulesinSweden are now basedon howthe data is used. GDPR Expanded Territorial Reach The GDPR Ruleswill have the followingimpactaccordingtoKhizarA. Sheikh,Chair,Privacy, Cybersecurity,andDataLaw,MandelbaumSalsburg,UnitedStates,ksheikh@lawfirm.ms: The GDPR regulatesdatacontrollersandprocessorsoutside the EUwhose processingactivitiesrelate to the offeringof goodsor services(evenif forfree) to,ormonitoringthe behaviorof,datasubjectsinthe EU. “Offeringgoodsorservices”ismore thanmere accessto a website oremail address,butcouldbe triggeredbyuse of language or currencygenerallyusedinone ormore MemberStateswiththe possibilityof orderinggoods/servicesthere and/ormentioningcustomersoruserswhoare in EU. “Monitoringof behavior”will occur,e.g.,where individualsare trackedonthe internetbytechniques whichapplya profile toenable decisionstobe made/predictpersonal preferences,etc. Thismeansthat a companyoutside the EU whichis targetingconsumersinthe EU will be subjecttothe GDPR. Role of Data Processors Data processorshave directobligationsforthe firsttime.Theseinclude anobligationto: maintaina writtenrecordof processingactivitiescarriedout onbehalf of eachcontroller; designate adata
  • 2. protectionofficerwhererequired; appointarepresentative(whennotestablishedinthe EU) in certain circumstances;and notifythe controlleronbecomingaware of apersonal databreach withoutundue delay. Provisionsoncrossbordertransfersalsoapplytoprocessors,andBindingCorporate Rulesfor processorsare formallyrecognized. New statusof dataprocessorswill impacthow dataprotection mattersare addressedinsupplyandothercommercial agreements. Notice / Consent Data controllersmustcontinue toprovide transparentinformationtodatasubjectsatthe time personal data isobtained. Existingformsof fairprocessingnoticesandconsentswill have tobe re-examinedas GDPR requirementsare more detailed. Consentmustbe freelygiven,specific,informed,and unambiguous,andmustbe as easyto withdraw asto give. Consentisnot freelygivenif the datasubject has no genuine andfree choice orisunable towithdraw orrefuse consentwithoutdetriment. Consent mustbe “explicit”forsensitive data. The datacontrollerisrequiredtobe able todemonstrate that consentwasgiven. Notice / Consent Issues Contracts Requestsforconsentshouldbe separate fromotherterms,andbe inclearand plainlanguage.Does consentprovidesavalidlegal groundforprocessingwherethere isasignificantimbalance betweenthe data subjectanddata controller? Whetherconsenthasbeenfreelygivendependson,e.g.,whetherthe performance of a contract ismade conditional onthe consenttoprocessingdatathat isnot necessaryto performthatcontract (mayaffecte-commerce services,amongothers). Employment MemberStatesmay provide more specificrulesforuse of consentinemploymentcontext. Marketing Where personal dataisprocessedfordirectmarketingthe datasubject will have arightto object. This rightmust be explicitlybroughttotheirattention. Children/ Parents MemberStatescan lowerthe age from whomdata can be collectedfrom16 to 13 (lackof harmonization). Data Transformation Whenis data nolongerthe data subjects’personal information? Penalties The GDPR establishesatieredapproach topenalties.Enablesthe DPAstoimpose finesforsome breachesof the greaterof 4% of annual worldwide revenuesor20 millioneuros(e.g.,breachof requirementsrelatingtointernational transfersorthe basicprinciplesforprocessing,suchasconditions for consent). Otherspecifiedbreacheswouldbe subjecttoa fine of the greaterof 2% of annual
  • 3. worldwide revenuesor10 millioneuros. A listof considerationswhenimposingfines(suchasthe nature,gravityanddurationof the breach) isavailable. Which Authority? The mechanismiscomplicatedasitdistinguishesbetweencross-borderanddomesticprocessing. There are complex cooperationandcoordinationproceduresforDPAs.Tohave theircasesdealtwithlocally, the GDPR containsa detailedregime withaLeadAuthorityandConcernedSupervisoryAuthorities workingtogether.The WP29** has providedguidance onhow toidentify aLeadSupervisoryAuthority. It remainstobe seenhowitwill workinpractice andwhetheritcan workwithoutforumshopping. GDPR = ENTERPRISEwide Trust The GDPR Ruleswill have the followingimpactaccordingtoThe GDPR Institute*and IanWest,Specialist inGDPR, Data Governance,DataPrivacy& Security,UnitedKingdom,ianwest348@gmail.com: Impact Do youcontrol or processpersonal dataaboutANY EU Citizens?If soyouhave to be GDPR compliantby 25th May 2018 or manage the implicationsof the finesandthe reputationaldamage of anyandevery Data Breach – includingCustomersEmployeesSuppliers Opportunity or Challenge? Fines,Lossof Customers, Reputational Damage,andCOSTof Compliance are keyaspectsof GDPR. GDPR involves EnterprisewideChange Management,PostRoom,andBoardRoom. It involves People,Process, Technology,andInformation. Key Questions What Personal Datado youhold – Customer,Employee,Supplier,Contractor,Sub-Contractor,Citizen, Patientetc. Where isthat Data Located?PC hard drive,Remote Storage orBackupDevice,OnPremise Database or ContentServer,orinThe Cloud. How are youusingthat Data? Do youhave Explicitor ImpliedPermissiontouse the datain the wayyou are usingit? Immediate ActionPlan SeekLegal Advice.ConductaPrivacyImpactAssessment.Complete aReadinessAssessmenttoaddress the keyquestions.Secure Executive Sponsorshipanda meaningful budget.DevelopaConsent ManagementStrategy. BuildaData SubjectAccessRequestprocessbeforeyougetswamped. Ensure youhave all your Breach Detectiontechnologyinplace –Database,ContentRepositories,Network Traffic,Dark Web8. Prepare forthe worst,and breathe a sigh of relief if itdoesn’thappen. The GDPR Institute HelpingyouresolveYOURGDPR Challenge &Maximise the GDPROpportunity. US businesses are re-evaluating their presenceinEurope
  • 4. The PWC GDPR Survey foundthatUS corporationsthatare heavilyinvestedinEurope will probablystay the course in the nearterm. Indeed,64% of executivesreportedthattheirtopstrategyforreducing GDPR exposure iscentralizationof datacentersinEurope.Justoverhalf (54%) saidtheyplanto de- identifyEuropeanpersonal datatoreduce exposure.The threatsof highfinesandimpactful injunctions, however,clearlyhave manyothersreconsideringthe importance of the Europeanmarket.Infact,32% of respondentsplantoreduce theirpresence inEurope,while26% intendtoexitthe EU market altogether. Companies are Spending millions to address GDPR 77% planto spend$1 millionormore on GDPR accordingto PWC.Securinga $1 millionbudgetfordata privacyhas beenmore anexceptionthanarule for manyAmericancorporations.The GDPR’spotential 4% fine of global revenues,however,haschangedbudgetappetitesformitigatingthisGDPRrisk.While 24% of respondentsplantospendunder$1 millionforGDPRpreparations,68% saidtheywill invest between$1millionand$10 million.Ninepercent(9%) expecttospendover$10 milliontoaddress GDPR obligations. More Learning Webcastabout GDPR Viewthis webinartolearnmore aboutthistopic at https://www.brighttalk.com/webcast/14723/259741 More reading *: AboutThe GDPR Institute,www.gdpr.institute . The GDPR Institute isaMembersOwnedNot-for- ProfitOrganisation. The Institutes’Purpose Createacommunityof Data Privacy,DataSecurityand Data Governance expertstoassistLarge,MediumandSmall Organisationsaddressthe challenge and maximise the opportunitycreatedbythe General DataProtectionRegulationGDPRChallengeOrGDPR Opportunity. **: WP29: https://iapp.org/news/a/wp29-releases-extensive-employee-privacy-guidance/ AboutAtlanticBT: We deliverabalancedapproachto security, https://www.atlanticbt.com/services/cybersecurity/