SlideShare a Scribd company logo
May 17, 2018
How to Comply with GDPR
Requirements: What every U.S.
Company needs to know
Preston Clark, J.D.
Joseph Lazzarotti,
Jason Gavejian &
Mary Costigan
Webinar Basics
1 Please ask questions
2 Full presentation will be sent out immediately following event
3 Webinar recording will be sent out next week
4 Post webinar communication plan
LMS
Integration
HRIS
Integration
Single Sign On
(SSO)
Shibboleth
About EVERFI
1,500+
20
Languages
Your Presenters
President of EVERFI’s Conduct & Culture division that
powers online compliance training programs for over 1,500
organizations worldwide. Preston was formerly Assistant
General Counsel for the University of Miami.
Preston Clark, J.D.
President at EVERFI
As a Certified Information Privacy Professional (CIPP), Mr
Gavejian focuses on the matrix of laws governing privacy,
security, and management of data. He is co-author of, and
regular contributor to, the firm’s Privacy Blog.
Jason C. Gavejian
Principal, Jackson Lewis
Advises multinational, national and regional companies on
emerging privacy and cybersecurity issues, including best
practices and preventive safeguards. Is also a Certified
Information Privacy Professional (CIPP) with IAPP.
Mary T. Costigan
Associate, Jackson Lewis
Founder and co-lead of the firm’s Privacy, e-Communication and
Data Security Practice, edits the firm’s Privacy Blog, and is a
Certified Information Privacy Professional (CIPP) with
International Association of Privacy Professionals (IAPP).
Joseph J. Lazzarotti
Principal, Jackson Lewis
• Represents management exclusively in every aspect of employment,
benefits, labor, and immigration law and related litigation, as well as
government relations in NYS & NYC.
• Over 800 attorneys in 57 locations nationwide
• Current caseload of over 6,500 litigations, approximately 650 class
actions.
• Founding member of L&E Global.
• A leader in educating employers about the laws of equal opportunity,
Jackson Lewis understands the importance of having a workforce that
reflects the various Communities it serves
About Jackson Lewis P.C.
Lawyer’s Disclaimer
Jackson Lewis P.C. has prepared the materials
contained in this presentation for the participants’
reference and general information in connection with
education seminars presented by the firm and its
attorneys. Attendees should consult with counsel
before taking any actions that could affect their legal
rights and should not consider these materials or
discussions about these materials to be legal or other
advice regarding any specific matter.
WHAT IS “GDPR”
AND WHO IS
SUBJECT TO IT?
• Adopted on April 14, 2016, by the EU Commission and
Parliament
• Replaces the 1995 Data Protection Directive (Directive
95/46/EC)
• Effective May 25, 2018
• Broader jurisdiction, greater harmonization, increased
penalties
The General Data Protection Regulation
(GDPR)
• Establishment
• Offering Goods and Services…Targeting
• Monitoring Behavior
• Resident v. Citizen
Jurisdiction, Territorial Scope
WHAT IS “PERSONAL
DATA” UNDER GDPR? IT’S
JUST LIKE THE U.S., RIGHT?
• Divergent historical context, purpose
• Personal data
• Very broad: Any information relating to an
identified or identifiable natural person
• Sensitive information
• Personal information
Personal Data v. Personal Information
WHAT DOES IT MEAN TO
BE “PROCESSING” DATA?
• Processing Means:
• Any operation or set of operations that are:
• Performed on personal data or on sets of personal data
• Whether on not by automated means
• Includes:
• Collection, recording, organization, structuring, storage,
adaption or alteration, retrieval, consultation, use, disclosure
by transmission, dissemination or otherwise making
available, alignment or combination, restriction, erasure or
destruction
Processing
IF WE’RE SUBJECT TO
GDPR, DO WE NEED TO
APPOINT A “DPO?”
• Appoint if core activities are:
• regular and systematic monitoring of data subjects on
a large scale, or
• processing special categories of data or data relating
to criminal convictions/offenses on a large scale
• Union representative v. DPO
• More stringent laws in member states
Data Protection Officer
WHAT ARE OUR BASIC
RESPONSIBILITIES AND
OBLIGATIONS?
• Data controller v. data processor
• Privacy impact assessment
• Notice
• Privacy by design
• Individual’s rights
• Recording processing activities
Responsibilties and Obligations
ARE THERE DATA BREACH
NOTIFICATION
REQUIREMENTS?
• What is a breach
• When to report to Supervisory Authority
• When to report to affected individuals
• Risk of harm exception
• Interactions with U.S. breach notification
requirements
Data Breaches
ANY SPECIAL RULES ON
CONSENT?
• Lawful basis
• Affirmative
• Voluntariness
• Bundling consents?
Consent
WHAT DO WE NEED TO
DO ABOUT DATA
SECURITY? ARE THERE
ANY SPECIAL
REQUIREMENTS?
• No specific framework or technologies required.
• Pseudonymization and encryption
• Privacy by design
• Data processor agreements
• Breach detection
Data Security
CAN OUR U.S. EMPLOYEES
ACCESS PERSONAL DATA
OF DATA SUBJECT IN THE
EU?
• Lawful basis
• “Adequate safeguards”
• Privacy Shield
• Model contracts
• Binding corporate rules
Accessing EU Data
WHAT HAPPENS IF WE DO
NOT COMPLY?
• Investigatory authority
• “Effective, proportionate and dissuasive”
• Level 1 fines - up to greater of 10,000,000 EUR or 2% of total worldwide
annual turnover.
• Level 2 fines - up to greater of 20,000,000 EUR or 4% of total worldwide
annual turnover.
• Judicial remedies
Enforcement
THE FUTURE
• Getting started
• Map your data
• Assess application and compliance
requirements
• Prepare employees (training)
• Coordinate with U.S. and other jurisdictions
• Document your steps
Take-Aways
Poll Question
How can we support you
further?
Thank You!
President of EVERFI’s Conduct & Culture division that
powers online compliance training programs for over 1,500
organizations worldwide. Preston was formerly Assistant
General Counsel for the University of Miami.
Preston Clark, J.D.
President at EVERFI
As a Certified Information Privacy Professional (CIPP), Mr
Gavejian focuses on the matrix of laws governing privacy,
security, and management of data. He is co-author of, and
regular contributor to, the firm’s Privacy Blog.
Jason C. Gavejian
Principal, Jackson Lewis
Advises multinational, national and regional companies on
emerging privacy and cybersecurity issues, including best
practices and preventive safeguards. Is also a Certified
Information Privacy Professional (CIPP) with IAPP.
Mary T. Costigan
Associate, Jackson Lewis
Founder and co-lead of the firm’s Privacy, e-Communication and
Data Security Practice, edits the firm’s Privacy Blog, and is a
Certified Information Privacy Professional (CIPP) with
International Association of Privacy Professionals (IAPP).
Joseph J. Lazzarotti
Principal, Jackson Lewis
May 17, 2018
How to Comply with GDPR
Requirements: What every U.S.
Company needs to know
Preston Clark, J.D.
Joseph Lazzarotti,
Jason Gavejian, &
Mary Costigan
END

More Related Content

What's hot

September CLE webinar: "Thorny Ethics Issues You Can't Ignore"
September CLE webinar: "Thorny Ethics Issues You Can't Ignore" September CLE webinar: "Thorny Ethics Issues You Can't Ignore"
September CLE webinar: "Thorny Ethics Issues You Can't Ignore"
LexisNexis
 
Gdpr workshop module_1
Gdpr workshop module_1Gdpr workshop module_1
Gdpr workshop module_1
S Sid Ahmed
 
Cyber Liability Insurance
Cyber Liability InsuranceCyber Liability Insurance
Cyber Liability Insurance
Graeme Newman
 
The Evolving Landscape of Collaborative Law Ethics
The Evolving Landscape of Collaborative Law EthicsThe Evolving Landscape of Collaborative Law Ethics
The Evolving Landscape of Collaborative Law Ethics
Jeffrey Fink
 
Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”
Bloomerang
 
Developing a Social Media Policy
Developing a Social Media PolicyDeveloping a Social Media Policy
Developing a Social Media PolicyEric Schwartzman
 
Baringa Partners GDPR / EU-US Privacy Shield Roundtable Discussion
Baringa Partners GDPR / EU-US Privacy Shield Roundtable DiscussionBaringa Partners GDPR / EU-US Privacy Shield Roundtable Discussion
Baringa Partners GDPR / EU-US Privacy Shield Roundtable Discussion
Jon Kumar
 
GDPR
GDPR GDPR
GDPR
Jon Kumar
 
Mitre: People in Progress
Mitre: People in ProgressMitre: People in Progress
Mitre: People in ProgressSoCo Partners
 

What's hot (10)

September CLE webinar: "Thorny Ethics Issues You Can't Ignore"
September CLE webinar: "Thorny Ethics Issues You Can't Ignore" September CLE webinar: "Thorny Ethics Issues You Can't Ignore"
September CLE webinar: "Thorny Ethics Issues You Can't Ignore"
 
Gdpr workshop module_1
Gdpr workshop module_1Gdpr workshop module_1
Gdpr workshop module_1
 
Cyber Liability Insurance
Cyber Liability InsuranceCyber Liability Insurance
Cyber Liability Insurance
 
The Evolving Landscape of Collaborative Law Ethics
The Evolving Landscape of Collaborative Law EthicsThe Evolving Landscape of Collaborative Law Ethics
The Evolving Landscape of Collaborative Law Ethics
 
Chapter 4
Chapter 4Chapter 4
Chapter 4
 
Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”
 
Developing a Social Media Policy
Developing a Social Media PolicyDeveloping a Social Media Policy
Developing a Social Media Policy
 
Baringa Partners GDPR / EU-US Privacy Shield Roundtable Discussion
Baringa Partners GDPR / EU-US Privacy Shield Roundtable DiscussionBaringa Partners GDPR / EU-US Privacy Shield Roundtable Discussion
Baringa Partners GDPR / EU-US Privacy Shield Roundtable Discussion
 
GDPR
GDPR GDPR
GDPR
 
Mitre: People in Progress
Mitre: People in ProgressMitre: People in Progress
Mitre: People in Progress
 

Similar to EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. Company needs to know

The Start-Up’s Guide to Privacy - MaRS Best Practices
The Start-Up’s Guide to Privacy - MaRS Best PracticesThe Start-Up’s Guide to Privacy - MaRS Best Practices
The Start-Up’s Guide to Privacy - MaRS Best Practices
MaRS Discovery District
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Iron Mountain
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
InfoGoTo
 
2 7-2013-big data and e-discovery
2 7-2013-big data and e-discovery2 7-2013-big data and e-discovery
2 7-2013-big data and e-discoveryExterro
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
Closing the Governance Gap - Enabling Governed Self-Service Analytics
Closing the Governance Gap  - Enabling Governed Self-Service AnalyticsClosing the Governance Gap  - Enabling Governed Self-Service Analytics
Closing the Governance Gap - Enabling Governed Self-Service Analytics
Privacera
 
Web Analytics and Privacy
Web Analytics and Privacy Web Analytics and Privacy
Web Analytics and Privacy
Piwik PRO
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to Privacy
FLUZO
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
Financial Poise
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
Dovetail Software
 
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdfData Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
CIOWomenMagazine
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
Rachel Aldighieri
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Financial Poise
 
2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx
2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx
2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx
VITNetflix
 
Towards data responsibility - how to put ideals into action
Towards data responsibility - how to put ideals into actionTowards data responsibility - how to put ideals into action
Towards data responsibility - how to put ideals into action
Mindtrek
 
MRS Roadshow 2019
MRS Roadshow 2019MRS Roadshow 2019
MRS Roadshow 2019
MRS
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
DATUM LLC
 
Implementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramImplementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramMSpadea
 
Ark presentation
Ark presentationArk presentation
Ark presentationbrentcarey
 

Similar to EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. Company needs to know (20)

The Start-Up’s Guide to Privacy - MaRS Best Practices
The Start-Up’s Guide to Privacy - MaRS Best PracticesThe Start-Up’s Guide to Privacy - MaRS Best Practices
The Start-Up’s Guide to Privacy - MaRS Best Practices
 
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...Build Your Foundation: Strategies and Tools for Managing Retention and Person...
Build Your Foundation: Strategies and Tools for Managing Retention and Person...
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
2 7-2013-big data and e-discovery
2 7-2013-big data and e-discovery2 7-2013-big data and e-discovery
2 7-2013-big data and e-discovery
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Closing the Governance Gap - Enabling Governed Self-Service Analytics
Closing the Governance Gap  - Enabling Governed Self-Service AnalyticsClosing the Governance Gap  - Enabling Governed Self-Service Analytics
Closing the Governance Gap - Enabling Governed Self-Service Analytics
 
Web Analytics and Privacy
Web Analytics and Privacy Web Analytics and Privacy
Web Analytics and Privacy
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to Privacy
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdfData Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx
2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx
2014 NCSAM - Data Security and Compliance—What You Need to Know.pptx
 
Towards data responsibility - how to put ideals into action
Towards data responsibility - how to put ideals into actionTowards data responsibility - how to put ideals into action
Towards data responsibility - how to put ideals into action
 
MRS Roadshow 2019
MRS Roadshow 2019MRS Roadshow 2019
MRS Roadshow 2019
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
 
Implementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramImplementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy Program
 
Ark presentation
Ark presentationArk presentation
Ark presentation
 

More from Michele Collu

EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance PostureEVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
Michele Collu
 
EVERFI: How To Build a Global Harassment Prevention Strategy
EVERFI: How To Build a Global Harassment Prevention StrategyEVERFI: How To Build a Global Harassment Prevention Strategy
EVERFI: How To Build a Global Harassment Prevention Strategy
Michele Collu
 
Webinar: Voices of courage-- college students speak from the frontlines of se...
Webinar: Voices of courage-- college students speak from the frontlines of se...Webinar: Voices of courage-- college students speak from the frontlines of se...
Webinar: Voices of courage-- college students speak from the frontlines of se...
Michele Collu
 
EVERFI/JL Webinar: New Sexual Harassment Training Mandates in New York
EVERFI/JL Webinar: New Sexual Harassment Training Mandates in New YorkEVERFI/JL Webinar: New Sexual Harassment Training Mandates in New York
EVERFI/JL Webinar: New Sexual Harassment Training Mandates in New York
Michele Collu
 
EVERFI Webinar: Ten years of impact engaging undergraduates in sexual assaul...
EVERFI Webinar: Ten years of impact engaging undergraduates in  sexual assaul...EVERFI Webinar: Ten years of impact engaging undergraduates in  sexual assaul...
EVERFI Webinar: Ten years of impact engaging undergraduates in sexual assaul...
Michele Collu
 
EVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual Assault
EVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual AssaultEVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual Assault
EVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual Assault
Michele Collu
 
EVERFI: Ongoing Alcohol Prevention Education
EVERFI: Ongoing Alcohol Prevention EducationEVERFI: Ongoing Alcohol Prevention Education
EVERFI: Ongoing Alcohol Prevention Education
Michele Collu
 
EVERFI: The Future of Workplace Harassment Prevention
EVERFI: The Future of Workplace Harassment PreventionEVERFI: The Future of Workplace Harassment Prevention
EVERFI: The Future of Workplace Harassment Prevention
Michele Collu
 
EVERFI: The Future of Harassment Prevention in Higher Ed
EVERFI: The Future of Harassment Prevention in Higher EdEVERFI: The Future of Harassment Prevention in Higher Ed
EVERFI: The Future of Harassment Prevention in Higher Ed
Michele Collu
 
EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...
EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...
EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...
Michele Collu
 
EVERFI: Understanding the Impact of State Marijuana Laws on Campus Prevention
EVERFI: Understanding the Impact of State Marijuana Laws on Campus PreventionEVERFI: Understanding the Impact of State Marijuana Laws on Campus Prevention
EVERFI: Understanding the Impact of State Marijuana Laws on Campus Prevention
Michele Collu
 
EVERFI: Addressing Dating & Domestic Violence in the Digital Age
EVERFI: Addressing Dating & Domestic Violence in the Digital AgeEVERFI: Addressing Dating & Domestic Violence in the Digital Age
EVERFI: Addressing Dating & Domestic Violence in the Digital Age
Michele Collu
 
EVERFI Webinar: NCAA Policy (Replay)
EVERFI Webinar: NCAA Policy (Replay)EVERFI Webinar: NCAA Policy (Replay)
EVERFI Webinar: NCAA Policy (Replay)
Michele Collu
 
How to Comply with the NCAA's New Sexual Assault Training Policy
How to Comply with the NCAA's New Sexual Assault Training PolicyHow to Comply with the NCAA's New Sexual Assault Training Policy
How to Comply with the NCAA's New Sexual Assault Training Policy
Michele Collu
 
EVERFI Webinar: Adapting sexual assault prevention to reach diverse students
EVERFI Webinar: Adapting sexual assault prevention to reach diverse studentsEVERFI Webinar: Adapting sexual assault prevention to reach diverse students
EVERFI Webinar: Adapting sexual assault prevention to reach diverse students
Michele Collu
 
EVERFI Webinar: Evidence Based Prescription Drugs Program
EVERFI Webinar: Evidence Based Prescription Drugs ProgramEVERFI Webinar: Evidence Based Prescription Drugs Program
EVERFI Webinar: Evidence Based Prescription Drugs Program
Michele Collu
 
EVERFI Webinar: Are We in Oz?
EVERFI Webinar: Are We in Oz? EVERFI Webinar: Are We in Oz?
EVERFI Webinar: Are We in Oz?
Michele Collu
 
EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...
EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...
EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...
Michele Collu
 
EVERFI Webinar: From Paper to Action: Using a Code of Conduct Effectively
EVERFI Webinar: From Paper to Action: Using a Code of Conduct EffectivelyEVERFI Webinar: From Paper to Action: Using a Code of Conduct Effectively
EVERFI Webinar: From Paper to Action: Using a Code of Conduct Effectively
Michele Collu
 
EVERFI Webinar: The Dear Colleague Letter Si Years Hence
EVERFI Webinar: The Dear Colleague Letter Si Years HenceEVERFI Webinar: The Dear Colleague Letter Si Years Hence
EVERFI Webinar: The Dear Colleague Letter Si Years Hence
Michele Collu
 

More from Michele Collu (20)

EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance PostureEVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
 
EVERFI: How To Build a Global Harassment Prevention Strategy
EVERFI: How To Build a Global Harassment Prevention StrategyEVERFI: How To Build a Global Harassment Prevention Strategy
EVERFI: How To Build a Global Harassment Prevention Strategy
 
Webinar: Voices of courage-- college students speak from the frontlines of se...
Webinar: Voices of courage-- college students speak from the frontlines of se...Webinar: Voices of courage-- college students speak from the frontlines of se...
Webinar: Voices of courage-- college students speak from the frontlines of se...
 
EVERFI/JL Webinar: New Sexual Harassment Training Mandates in New York
EVERFI/JL Webinar: New Sexual Harassment Training Mandates in New YorkEVERFI/JL Webinar: New Sexual Harassment Training Mandates in New York
EVERFI/JL Webinar: New Sexual Harassment Training Mandates in New York
 
EVERFI Webinar: Ten years of impact engaging undergraduates in sexual assaul...
EVERFI Webinar: Ten years of impact engaging undergraduates in  sexual assaul...EVERFI Webinar: Ten years of impact engaging undergraduates in  sexual assaul...
EVERFI Webinar: Ten years of impact engaging undergraduates in sexual assaul...
 
EVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual Assault
EVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual AssaultEVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual Assault
EVERFI/Jackson Lewis: NCAA Compliance: Raising the Bar to Prevent Sexual Assault
 
EVERFI: Ongoing Alcohol Prevention Education
EVERFI: Ongoing Alcohol Prevention EducationEVERFI: Ongoing Alcohol Prevention Education
EVERFI: Ongoing Alcohol Prevention Education
 
EVERFI: The Future of Workplace Harassment Prevention
EVERFI: The Future of Workplace Harassment PreventionEVERFI: The Future of Workplace Harassment Prevention
EVERFI: The Future of Workplace Harassment Prevention
 
EVERFI: The Future of Harassment Prevention in Higher Ed
EVERFI: The Future of Harassment Prevention in Higher EdEVERFI: The Future of Harassment Prevention in Higher Ed
EVERFI: The Future of Harassment Prevention in Higher Ed
 
EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...
EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...
EVERFI: Beyond Freshman Year: Engaging Students in Ongoing Sexual Violence Pr...
 
EVERFI: Understanding the Impact of State Marijuana Laws on Campus Prevention
EVERFI: Understanding the Impact of State Marijuana Laws on Campus PreventionEVERFI: Understanding the Impact of State Marijuana Laws on Campus Prevention
EVERFI: Understanding the Impact of State Marijuana Laws on Campus Prevention
 
EVERFI: Addressing Dating & Domestic Violence in the Digital Age
EVERFI: Addressing Dating & Domestic Violence in the Digital AgeEVERFI: Addressing Dating & Domestic Violence in the Digital Age
EVERFI: Addressing Dating & Domestic Violence in the Digital Age
 
EVERFI Webinar: NCAA Policy (Replay)
EVERFI Webinar: NCAA Policy (Replay)EVERFI Webinar: NCAA Policy (Replay)
EVERFI Webinar: NCAA Policy (Replay)
 
How to Comply with the NCAA's New Sexual Assault Training Policy
How to Comply with the NCAA's New Sexual Assault Training PolicyHow to Comply with the NCAA's New Sexual Assault Training Policy
How to Comply with the NCAA's New Sexual Assault Training Policy
 
EVERFI Webinar: Adapting sexual assault prevention to reach diverse students
EVERFI Webinar: Adapting sexual assault prevention to reach diverse studentsEVERFI Webinar: Adapting sexual assault prevention to reach diverse students
EVERFI Webinar: Adapting sexual assault prevention to reach diverse students
 
EVERFI Webinar: Evidence Based Prescription Drugs Program
EVERFI Webinar: Evidence Based Prescription Drugs ProgramEVERFI Webinar: Evidence Based Prescription Drugs Program
EVERFI Webinar: Evidence Based Prescription Drugs Program
 
EVERFI Webinar: Are We in Oz?
EVERFI Webinar: Are We in Oz? EVERFI Webinar: Are We in Oz?
EVERFI Webinar: Are We in Oz?
 
EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...
EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...
EVERFI webinar: Why We Need a Paradigm Shift in the College Student Drinking ...
 
EVERFI Webinar: From Paper to Action: Using a Code of Conduct Effectively
EVERFI Webinar: From Paper to Action: Using a Code of Conduct EffectivelyEVERFI Webinar: From Paper to Action: Using a Code of Conduct Effectively
EVERFI Webinar: From Paper to Action: Using a Code of Conduct Effectively
 
EVERFI Webinar: The Dear Colleague Letter Si Years Hence
EVERFI Webinar: The Dear Colleague Letter Si Years HenceEVERFI Webinar: The Dear Colleague Letter Si Years Hence
EVERFI Webinar: The Dear Colleague Letter Si Years Hence
 

Recently uploaded

Chapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptxChapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptx
Mohd Adib Abd Muin, Senior Lecturer at Universiti Utara Malaysia
 
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXXPhrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
MIRIAMSALINAS13
 
Thesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.pptThesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.ppt
EverAndrsGuerraGuerr
 
ESC Beyond Borders _From EU to You_ InfoPack general.pdf
ESC Beyond Borders _From EU to You_ InfoPack general.pdfESC Beyond Borders _From EU to You_ InfoPack general.pdf
ESC Beyond Borders _From EU to You_ InfoPack general.pdf
Fundacja Rozwoju Społeczeństwa Przedsiębiorczego
 
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
Nguyen Thanh Tu Collection
 
How to Break the cycle of negative Thoughts
How to Break the cycle of negative ThoughtsHow to Break the cycle of negative Thoughts
How to Break the cycle of negative Thoughts
Col Mukteshwar Prasad
 
Introduction to Quality Improvement Essentials
Introduction to Quality Improvement EssentialsIntroduction to Quality Improvement Essentials
Introduction to Quality Improvement Essentials
Excellence Foundation for South Sudan
 
Unit 2- Research Aptitude (UGC NET Paper I).pdf
Unit 2- Research Aptitude (UGC NET Paper I).pdfUnit 2- Research Aptitude (UGC NET Paper I).pdf
Unit 2- Research Aptitude (UGC NET Paper I).pdf
Thiyagu K
 
Home assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdfHome assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdf
Tamralipta Mahavidyalaya
 
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup   New Member Orientation and Q&A (May 2024).pdfWelcome to TechSoup   New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
TechSoup
 
Language Across the Curriculm LAC B.Ed.
Language Across the  Curriculm LAC B.Ed.Language Across the  Curriculm LAC B.Ed.
Language Across the Curriculm LAC B.Ed.
Atul Kumar Singh
 
Supporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptxSupporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptx
Jisc
 
The geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideasThe geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideas
GeoBlogs
 
Ethnobotany and Ethnopharmacology ......
Ethnobotany and Ethnopharmacology ......Ethnobotany and Ethnopharmacology ......
Ethnobotany and Ethnopharmacology ......
Ashokrao Mane college of Pharmacy Peth-Vadgaon
 
Unit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdfUnit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdf
Thiyagu K
 
How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17
Celine George
 
Fish and Chips - have they had their chips
Fish and Chips - have they had their chipsFish and Chips - have they had their chips
Fish and Chips - have they had their chips
GeoBlogs
 
The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official Publication
Delapenabediema
 
Polish students' mobility in the Czech Republic
Polish students' mobility in the Czech RepublicPolish students' mobility in the Czech Republic
Polish students' mobility in the Czech Republic
Anna Sz.
 
The Art Pastor's Guide to Sabbath | Steve Thomason
The Art Pastor's Guide to Sabbath | Steve ThomasonThe Art Pastor's Guide to Sabbath | Steve Thomason
The Art Pastor's Guide to Sabbath | Steve Thomason
Steve Thomason
 

Recently uploaded (20)

Chapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptxChapter 3 - Islamic Banking Products and Services.pptx
Chapter 3 - Islamic Banking Products and Services.pptx
 
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXXPhrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
Phrasal Verbs.XXXXXXXXXXXXXXXXXXXXXXXXXX
 
Thesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.pptThesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.ppt
 
ESC Beyond Borders _From EU to You_ InfoPack general.pdf
ESC Beyond Borders _From EU to You_ InfoPack general.pdfESC Beyond Borders _From EU to You_ InfoPack general.pdf
ESC Beyond Borders _From EU to You_ InfoPack general.pdf
 
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
GIÁO ÁN DẠY THÊM (KẾ HOẠCH BÀI BUỔI 2) - TIẾNG ANH 8 GLOBAL SUCCESS (2 CỘT) N...
 
How to Break the cycle of negative Thoughts
How to Break the cycle of negative ThoughtsHow to Break the cycle of negative Thoughts
How to Break the cycle of negative Thoughts
 
Introduction to Quality Improvement Essentials
Introduction to Quality Improvement EssentialsIntroduction to Quality Improvement Essentials
Introduction to Quality Improvement Essentials
 
Unit 2- Research Aptitude (UGC NET Paper I).pdf
Unit 2- Research Aptitude (UGC NET Paper I).pdfUnit 2- Research Aptitude (UGC NET Paper I).pdf
Unit 2- Research Aptitude (UGC NET Paper I).pdf
 
Home assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdfHome assignment II on Spectroscopy 2024 Answers.pdf
Home assignment II on Spectroscopy 2024 Answers.pdf
 
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup   New Member Orientation and Q&A (May 2024).pdfWelcome to TechSoup   New Member Orientation and Q&A (May 2024).pdf
Welcome to TechSoup New Member Orientation and Q&A (May 2024).pdf
 
Language Across the Curriculm LAC B.Ed.
Language Across the  Curriculm LAC B.Ed.Language Across the  Curriculm LAC B.Ed.
Language Across the Curriculm LAC B.Ed.
 
Supporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptxSupporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptx
 
The geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideasThe geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideas
 
Ethnobotany and Ethnopharmacology ......
Ethnobotany and Ethnopharmacology ......Ethnobotany and Ethnopharmacology ......
Ethnobotany and Ethnopharmacology ......
 
Unit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdfUnit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdf
 
How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17How to Make a Field invisible in Odoo 17
How to Make a Field invisible in Odoo 17
 
Fish and Chips - have they had their chips
Fish and Chips - have they had their chipsFish and Chips - have they had their chips
Fish and Chips - have they had their chips
 
The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official Publication
 
Polish students' mobility in the Czech Republic
Polish students' mobility in the Czech RepublicPolish students' mobility in the Czech Republic
Polish students' mobility in the Czech Republic
 
The Art Pastor's Guide to Sabbath | Steve Thomason
The Art Pastor's Guide to Sabbath | Steve ThomasonThe Art Pastor's Guide to Sabbath | Steve Thomason
The Art Pastor's Guide to Sabbath | Steve Thomason
 

EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. Company needs to know

  • 1. May 17, 2018 How to Comply with GDPR Requirements: What every U.S. Company needs to know Preston Clark, J.D. Joseph Lazzarotti, Jason Gavejian & Mary Costigan
  • 2. Webinar Basics 1 Please ask questions 2 Full presentation will be sent out immediately following event 3 Webinar recording will be sent out next week 4 Post webinar communication plan
  • 4. Your Presenters President of EVERFI’s Conduct & Culture division that powers online compliance training programs for over 1,500 organizations worldwide. Preston was formerly Assistant General Counsel for the University of Miami. Preston Clark, J.D. President at EVERFI As a Certified Information Privacy Professional (CIPP), Mr Gavejian focuses on the matrix of laws governing privacy, security, and management of data. He is co-author of, and regular contributor to, the firm’s Privacy Blog. Jason C. Gavejian Principal, Jackson Lewis Advises multinational, national and regional companies on emerging privacy and cybersecurity issues, including best practices and preventive safeguards. Is also a Certified Information Privacy Professional (CIPP) with IAPP. Mary T. Costigan Associate, Jackson Lewis Founder and co-lead of the firm’s Privacy, e-Communication and Data Security Practice, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with International Association of Privacy Professionals (IAPP). Joseph J. Lazzarotti Principal, Jackson Lewis
  • 5. • Represents management exclusively in every aspect of employment, benefits, labor, and immigration law and related litigation, as well as government relations in NYS & NYC. • Over 800 attorneys in 57 locations nationwide • Current caseload of over 6,500 litigations, approximately 650 class actions. • Founding member of L&E Global. • A leader in educating employers about the laws of equal opportunity, Jackson Lewis understands the importance of having a workforce that reflects the various Communities it serves About Jackson Lewis P.C.
  • 6. Lawyer’s Disclaimer Jackson Lewis P.C. has prepared the materials contained in this presentation for the participants’ reference and general information in connection with education seminars presented by the firm and its attorneys. Attendees should consult with counsel before taking any actions that could affect their legal rights and should not consider these materials or discussions about these materials to be legal or other advice regarding any specific matter.
  • 7. WHAT IS “GDPR” AND WHO IS SUBJECT TO IT?
  • 8. • Adopted on April 14, 2016, by the EU Commission and Parliament • Replaces the 1995 Data Protection Directive (Directive 95/46/EC) • Effective May 25, 2018 • Broader jurisdiction, greater harmonization, increased penalties The General Data Protection Regulation (GDPR)
  • 9. • Establishment • Offering Goods and Services…Targeting • Monitoring Behavior • Resident v. Citizen Jurisdiction, Territorial Scope
  • 10. WHAT IS “PERSONAL DATA” UNDER GDPR? IT’S JUST LIKE THE U.S., RIGHT?
  • 11. • Divergent historical context, purpose • Personal data • Very broad: Any information relating to an identified or identifiable natural person • Sensitive information • Personal information Personal Data v. Personal Information
  • 12. WHAT DOES IT MEAN TO BE “PROCESSING” DATA?
  • 13. • Processing Means: • Any operation or set of operations that are: • Performed on personal data or on sets of personal data • Whether on not by automated means • Includes: • Collection, recording, organization, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction Processing
  • 14. IF WE’RE SUBJECT TO GDPR, DO WE NEED TO APPOINT A “DPO?”
  • 15. • Appoint if core activities are: • regular and systematic monitoring of data subjects on a large scale, or • processing special categories of data or data relating to criminal convictions/offenses on a large scale • Union representative v. DPO • More stringent laws in member states Data Protection Officer
  • 16. WHAT ARE OUR BASIC RESPONSIBILITIES AND OBLIGATIONS?
  • 17. • Data controller v. data processor • Privacy impact assessment • Notice • Privacy by design • Individual’s rights • Recording processing activities Responsibilties and Obligations
  • 18. ARE THERE DATA BREACH NOTIFICATION REQUIREMENTS?
  • 19. • What is a breach • When to report to Supervisory Authority • When to report to affected individuals • Risk of harm exception • Interactions with U.S. breach notification requirements Data Breaches
  • 20. ANY SPECIAL RULES ON CONSENT?
  • 21. • Lawful basis • Affirmative • Voluntariness • Bundling consents? Consent
  • 22. WHAT DO WE NEED TO DO ABOUT DATA SECURITY? ARE THERE ANY SPECIAL REQUIREMENTS?
  • 23. • No specific framework or technologies required. • Pseudonymization and encryption • Privacy by design • Data processor agreements • Breach detection Data Security
  • 24. CAN OUR U.S. EMPLOYEES ACCESS PERSONAL DATA OF DATA SUBJECT IN THE EU?
  • 25. • Lawful basis • “Adequate safeguards” • Privacy Shield • Model contracts • Binding corporate rules Accessing EU Data
  • 26. WHAT HAPPENS IF WE DO NOT COMPLY?
  • 27. • Investigatory authority • “Effective, proportionate and dissuasive” • Level 1 fines - up to greater of 10,000,000 EUR or 2% of total worldwide annual turnover. • Level 2 fines - up to greater of 20,000,000 EUR or 4% of total worldwide annual turnover. • Judicial remedies Enforcement
  • 29. • Getting started • Map your data • Assess application and compliance requirements • Prepare employees (training) • Coordinate with U.S. and other jurisdictions • Document your steps Take-Aways
  • 30. Poll Question How can we support you further?
  • 31. Thank You! President of EVERFI’s Conduct & Culture division that powers online compliance training programs for over 1,500 organizations worldwide. Preston was formerly Assistant General Counsel for the University of Miami. Preston Clark, J.D. President at EVERFI As a Certified Information Privacy Professional (CIPP), Mr Gavejian focuses on the matrix of laws governing privacy, security, and management of data. He is co-author of, and regular contributor to, the firm’s Privacy Blog. Jason C. Gavejian Principal, Jackson Lewis Advises multinational, national and regional companies on emerging privacy and cybersecurity issues, including best practices and preventive safeguards. Is also a Certified Information Privacy Professional (CIPP) with IAPP. Mary T. Costigan Associate, Jackson Lewis Founder and co-lead of the firm’s Privacy, e-Communication and Data Security Practice, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with International Association of Privacy Professionals (IAPP). Joseph J. Lazzarotti Principal, Jackson Lewis
  • 32. May 17, 2018 How to Comply with GDPR Requirements: What every U.S. Company needs to know Preston Clark, J.D. Joseph Lazzarotti, Jason Gavejian, & Mary Costigan
  • 33. END