SlideShare a Scribd company logo
1 of 23
Download to read offline
In partnership with
European Risk Manager Report 2020
Edition
Top critical threats to the organisation’s growth prospects within the
next 12 months
CYBER THREAT
UNCERTAIN ECONOMIC
GROWTH
AVAILABILITY OF KEY
SKILLS
DATA FRAUD OR THEFT
OVER-REGULATION
CYBER THREAT
UNCERTAIN ECONOMIC
GROWTH
GEOPOLITICAL
UNCERTAINLY
OVER-REGULATION
CHANGING CONSUMER
BEHAVIOUR
TOP RISK 2020TOP RISK 2018
37% 39%
24%
How do you deal with risks arising from emerging technologies ?
Identification and assessment of risks prior to adoption of new technologies by the
business
Identification and assessment of emerging technologies used by the business
Analysis and remediation of any insurance coverage gaps
Risks in Focus 2021
Cybersecurity and Data security as top risk again!
GDPR :expert’s introduction
Ralf Herold
Senior Vice President, Corporate
Audit BASF
Jérôme Avot
Group Risk Officer and
Data Protection Officer at
Faurecia
Olivier Micol
Head of Data Protection Unit at the
European Commission, Directorate-
General for Justice
GDPR :Expert Talk
Olivier Micol
Head of Data Protection Unit at the
European Commission, Directorate-
General for Justice
▪ Key elements of the recent
GDPR evaluation report of
the European Commission
▪ share the latest data and
feedback from companies
and civil society
▪ overview of future planned
initiatives
GDPR :Polling question #1
How would you assess the level of divergence in the
enforcement of GDPR regulation by DPA in EU?
❑ High
❑ Medium
❑ Low
GDPR :Polling question #2
How do you evaluate your interaction with the DPA in
your country?
❑ Very Good
❑ Good
❑ Bad
❑ Very Bad
GDPR :Expert Talk
➢ About FAURECIA
➢ Impact of the GDPR on the activities
➢ How to be both DPO and Risk Manager ?
➢ Ongoing challenges
➢ Covid 19 and GDPR
Jérôme Avot
Group Risk Office and Data
Protection Officer, FAURECIA
About FAURECIA
Impact of the GDPR on the activities
• While the GDPR was mostly generating fear, uncertainty and doubts before its application in May 2018… the
benefits, after more than two years, are widely recognized !
• It forced helped companies to perform a comprehensive inventory of all their data processing activities
• … and act on those which were not (fully) compliant (security, data retention, consent…)
• It helped to start projects (especially security related) which were not considered as “priority 1”. A new
regulation is a good excuse to get budget ☺
• Companies are now taking more care regarding their own sub-contractors (from a legal and practical
standpoint) including requirement for certification, audits, …
• Most companies are now ready in case of Data Breach, they know how to deal with new “data
processing” (privacy by design) and are used to respond to Data Subject Request.
• Wider training program to employees regarding data protection contributing to the reinforcement of the
overall cyber-security of the company
GDPR is a journey, not a destination, but companies have mostly embraced the spirit of GDPR and are
moving in the right direction to drastically improve personal data protection.
How to be both DPO and Risk
Manager ?
Being a DPO and Risk Manager is totally compatible…
but not all Risk Manager can be DPO and not all DPO could be Risk Manager
• The word “Risk” is being mentioned more than 78 times in the official GDPR regulation
• Risk Management is one of the pillars of the GDPR Regulation
• So who else better than a “Risk Manager” to manage “Personal Data Protection” risk ?
• This is not that obvious:
• The DPO is usually considered as a “five-legged sheep” :
• Need for (even basic) legal knowledge
• Need for Information System Security knowledge
• Need to be pedagogue, good ability to communicate and train people
• Need to have a good internal network and be recognized
• Need to be able to assess risks
• Not all “Risk Managers” will therefore do the job ☺
• However being both Risk Manager and DPO has many benefits including:
• Benefits from “risk oriented” mindset and ensure perfect alignment with Risk Management
methodology
• Good mix between daily actions as a “DPO” and more medium/long term action as “Risk Manager”
• Being able to assess this specific risk at the right level in the overall risk matrix
Ongoing challenges ?
• Three main ongoing challenges to deal with in the current context:
• Ensure continuous GDPR compliance
• How to make sure that all new and existing data processing activities are recorded and compliant ?
• How to ensure that all changes are being done in compliance with GDPR mindset ?
• Spot the weakest link
• Security of data is a matter of weakest link and the difficulty is to find out what could be this
weakest link leading to a data breach.
• How well protected are your test environments ? Does your replicated data are being
anonymized ?
• Where are your backup stored and how secure they are ?
• How well protected is your sub-contractor laptop holding a backup of all your data ?
• Deal with the invalidation of the Privacy Shield (since July 2020)
• Should we put in place Standard Contractual Clauses (SCCs) or even Binding Corporate Rules (BCRs)
?
• Should we start compartmentalizing data in different regions ? (e-mails for instance)
• Should we suspend temporarily such transfers until clear guidance is released ?
Covid-19 and GPDR
During this difficult and complex period, all Europeans DPA are making efforts to provide guidance and
assistance to companies on this complex topic… but companies still need to apply GDPR principles and be
agile in a fast-paced changing environment !
• Employers have obligations to ensure the health and safety of employees while at work but they also need
to ensure compliance with GDPR: A real challenge in this Covid-19 context !
• Health information is classed as “special category of personal data” under GDPR meaning a Data
Protection Impact Assessment should be done in order to understand the risks associated with
such kind of data processing and… ensure those risks are properly mitigated !
• Typical steps include:
• Identify clear needs (“purpose limitation” and “data minimization” principles) for each cases
(temperature screening, CCTV, close contacts…) and collect ONLY NECESSARY data
• Identity a “Lawful basis of processing” (and forget about consent)
• Prepare a “Privacy Policy” (“right to be informed” principle)
• Ensure Security and Confidentiality of data (“security” principle)
• And… document the measures taken (“accountability” principle)
GDPR :Expert Talk
➢ About BASF
➢ Impact of the GDPR on the activities
➢ The role of internal auditors: what has changed?
➢ Ongoing challenges
➢ Covid 19 and GDPR
Ralf Herold
Senior Vice President, Corporate
Audit BASF
Facts important to know: Objectives of the EU-GDPR – protection of
natural person, and more..!
Striving for a balance of all 3 objectives in a common EU-market with same market rules &
conditions for all market subjects  protection of personal data is not an absolute right
GDPR
Recital 1
“protection of natural persons in relation to the processing of
personal data
Art 1 GDPR & Recital 9
“free flow of personal data throughout the Union”
Recital 2
Recital 4
“Economic union, strengthening EU market
development”
“freedom to conduct business”
17
NationNation
Enterprise Enterprise
Employee Customer/Vendor
2
3
4
5 6
1
Nation/Government
Enterprise/Company
1. Nation/Nation: Contracts & No-Spy
2. Government/Enterprise: Regulatory Business Framework
3. Government/Citizen: Civil Rights/Right to be left alone/Data ownership and disposition rights
 National Security & Law Enforcement – “Social Contract: Citizens  Government”
4. Enterprise/Enterprise: Contracts – IP rights – Anti-Trust Regulations
5. Enterprise/Employee: Contracts - Consensus
6. Enterprise/Customer/Vendor: Contracts - Consensus
Data Subjects
Protection of the Rights of a Natural Person –
What Enterprises can do and have to focus on
➢ Enterprises adhere
to rules
➢ Can‘t solve political
disputes or Nations
or Government
affairs
BASF SE = Main
Establishment
BASF Group EU-Companies
= Group Of Undertakings
Lead Supervisory Authority
The State Commissioner for
Data Protection and the
Freedom of Information
Rhineland-Palatinate
LfDI RLP
Data Protection Commissioner
by Country
Consistency Mechanism
BASF applies the One-Stop-Shop Concept (Art. 56 & Art. 60 GDPR)
Data Protection @ BASF
➢ by design Europa
➢ de facto Global
Questions & Answers
Supporting documents
Thank you
About FERMA
FERMA brings together 22 risk management associations in 21 European countries.
They represent nearly 5,000 professional risk managers active in a wide
range of business sectors.
The Federation of European Risk Management Associations (FERMA)
speaks for the risk management profession in Europe.
FERMA acts on its behalf at European level and promotes the risk
management profession.
FERMA provides a risk management perspective on European issues and
strengthens the profession through a European risk management
certification (rimap).
www.ferma.eu
About ECIIA
ECIIA gives voice to 48.000 Internal Auditors in 34 countries from wider Europe.
The European Confederation of Institutes of Internal Auditing (ECIIA) is the
voice of internal audit in Europe.
Our role is to enhance corporate governance through the promotion of
the professional practice of internal auditing.
The ECIIA mission is to further the development of good corporate
governance and internal audit at the European level, through
• Knowledge sharing
• Developing key relationships
• Impacting the regulatory environment, by dealing with the European
Union, its Parliament and the European Authorities.

More Related Content

What's hot

Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management FERMA
 
HBR - Zurich - FERMAZ - PRIMO Cyber Risks Report
HBR - Zurich - FERMAZ - PRIMO Cyber Risks ReportHBR - Zurich - FERMAZ - PRIMO Cyber Risks Report
HBR - Zurich - FERMAZ - PRIMO Cyber Risks ReportFERMA
 
Sustainability as risk management
Sustainability as risk managementSustainability as risk management
Sustainability as risk managementMetso Group
 
ESG Risks and Thai Banks: Time to Walk the Talk
ESG Risks and Thai Banks: Time to Walk the TalkESG Risks and Thai Banks: Time to Walk the Talk
ESG Risks and Thai Banks: Time to Walk the TalkSarinee Achavanuntakul
 
Sustainable Brands New Metrics: The evolution of social and human capital man...
Sustainable Brands New Metrics: The evolution of social and human capital man...Sustainable Brands New Metrics: The evolution of social and human capital man...
Sustainable Brands New Metrics: The evolution of social and human capital man...Mike Wallace
 
Managing the ESG Ecosystem US EPA_Feb_2021
Managing the ESG Ecosystem US EPA_Feb_2021Managing the ESG Ecosystem US EPA_Feb_2021
Managing the ESG Ecosystem US EPA_Feb_2021Mike Wallace
 
EMEA Insurers Snapshot - Regional Snapshot
EMEA Insurers Snapshot - Regional SnapshotEMEA Insurers Snapshot - Regional Snapshot
EMEA Insurers Snapshot - Regional SnapshotMelissa Scianna
 
Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...
Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...
Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...NarimanMaalouf
 
Sustainability Knowledge Group launches new digital reporting tool
Sustainability Knowledge Group launches new digital reporting toolSustainability Knowledge Group launches new digital reporting tool
Sustainability Knowledge Group launches new digital reporting toolSustainability Knowledge Group
 
Sustainability and Integrated Reporting
Sustainability and Integrated Reporting Sustainability and Integrated Reporting
Sustainability and Integrated Reporting paul young cpa, cga
 

What's hot (11)

Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management Ferma report: Artificial Intelligence applied to Risk Management
Ferma report: Artificial Intelligence applied to Risk Management
 
HBR - Zurich - FERMAZ - PRIMO Cyber Risks Report
HBR - Zurich - FERMAZ - PRIMO Cyber Risks ReportHBR - Zurich - FERMAZ - PRIMO Cyber Risks Report
HBR - Zurich - FERMAZ - PRIMO Cyber Risks Report
 
Sustainability as risk management
Sustainability as risk managementSustainability as risk management
Sustainability as risk management
 
Sustainability & Risk Management
Sustainability & Risk ManagementSustainability & Risk Management
Sustainability & Risk Management
 
ESG Risks and Thai Banks: Time to Walk the Talk
ESG Risks and Thai Banks: Time to Walk the TalkESG Risks and Thai Banks: Time to Walk the Talk
ESG Risks and Thai Banks: Time to Walk the Talk
 
Sustainable Brands New Metrics: The evolution of social and human capital man...
Sustainable Brands New Metrics: The evolution of social and human capital man...Sustainable Brands New Metrics: The evolution of social and human capital man...
Sustainable Brands New Metrics: The evolution of social and human capital man...
 
Managing the ESG Ecosystem US EPA_Feb_2021
Managing the ESG Ecosystem US EPA_Feb_2021Managing the ESG Ecosystem US EPA_Feb_2021
Managing the ESG Ecosystem US EPA_Feb_2021
 
EMEA Insurers Snapshot - Regional Snapshot
EMEA Insurers Snapshot - Regional SnapshotEMEA Insurers Snapshot - Regional Snapshot
EMEA Insurers Snapshot - Regional Snapshot
 
Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...
Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...
Insurance Role in a Climate Change Constraint World: UAE Motor Best Practice ...
 
Sustainability Knowledge Group launches new digital reporting tool
Sustainability Knowledge Group launches new digital reporting toolSustainability Knowledge Group launches new digital reporting tool
Sustainability Knowledge Group launches new digital reporting tool
 
Sustainability and Integrated Reporting
Sustainability and Integrated Reporting Sustainability and Integrated Reporting
Sustainability and Integrated Reporting
 

Similar to GDPR & corporate Governance, Evaluation after 2 years implementation

EU GDPR: What You Really Need to Know
EU GDPR: What You Really Need to Know EU GDPR: What You Really Need to Know
EU GDPR: What You Really Need to Know Sarah Crabb
 
The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...IT Governance Ltd
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesDimitri Sirota
 
CWIN17 telford gdpr – threat, overhead or opportunity - doug davidson
CWIN17 telford   gdpr – threat, overhead or opportunity - doug davidsonCWIN17 telford   gdpr – threat, overhead or opportunity - doug davidson
CWIN17 telford gdpr – threat, overhead or opportunity - doug davidsonCapgemini
 
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-smIBM Sverige
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacyGuyVanderSande
 
Meeting the cyber risk challenge
Meeting the cyber risk challengeMeeting the cyber risk challenge
Meeting the cyber risk challengeFERMA
 
Journey2018: Surviving and thriving under GDPR
Journey2018: Surviving and thriving under GDPR  Journey2018: Surviving and thriving under GDPR
Journey2018: Surviving and thriving under GDPR Yieldify
 
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...confluent
 
The impact of GDPR on UK employers
The impact of GDPR on UK employersThe impact of GDPR on UK employers
The impact of GDPR on UK employersRalf Braga
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018Dean Evans
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRMatt Stubbs
 
GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.James Seville
 

Similar to GDPR & corporate Governance, Evaluation after 2 years implementation (20)

EU GDPR: What You Really Need to Know
EU GDPR: What You Really Need to Know EU GDPR: What You Really Need to Know
EU GDPR: What You Really Need to Know
 
The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...The GDPR and its requirements for implementing data protection impact assessm...
The GDPR and its requirements for implementing data protection impact assessm...
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
CWIN17 telford gdpr – threat, overhead or opportunity - doug davidson
CWIN17 telford   gdpr – threat, overhead or opportunity - doug davidsonCWIN17 telford   gdpr – threat, overhead or opportunity - doug davidson
CWIN17 telford gdpr – threat, overhead or opportunity - doug davidson
 
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacy
 
Meeting the cyber risk challenge
Meeting the cyber risk challengeMeeting the cyber risk challenge
Meeting the cyber risk challenge
 
Journey2018: Surviving and thriving under GDPR
Journey2018: Surviving and thriving under GDPR  Journey2018: Surviving and thriving under GDPR
Journey2018: Surviving and thriving under GDPR
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...
 
2018 Client Briefing GDPR
2018 Client Briefing GDPR2018 Client Briefing GDPR
2018 Client Briefing GDPR
 
BDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEsBDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEs
 
The impact of GDPR on UK employers
The impact of GDPR on UK employersThe impact of GDPR on UK employers
The impact of GDPR on UK employers
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPR
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
 

More from FERMA

FERMA contribution to the French Presidency agenda
FERMA contribution to the French Presidency agendaFERMA contribution to the French Presidency agenda
FERMA contribution to the French Presidency agendaFERMA
 
The role of risk management in corporate resilience
The role of risk management in corporate resilienceThe role of risk management in corporate resilience
The role of risk management in corporate resilienceFERMA
 
Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience FERMA
 
People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...FERMA
 
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...FERMA
 
Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020FERMA
 
Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020FERMA
 
George Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland WaterGeorge Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland WaterFERMA
 
The European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentationThe European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentationFERMA
 
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...FERMA
 
Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019FERMA
 
Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?FERMA
 
FERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber SecurityFERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber SecurityFERMA
 
Ferma European Risk Manager Report 2018
Ferma European Risk Manager Report 2018Ferma European Risk Manager Report 2018
Ferma European Risk Manager Report 2018FERMA
 
Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018FERMA
 
European risk management sustainability seminar report
European risk management sustainability seminar reportEuropean risk management sustainability seminar report
European risk management sustainability seminar reportFERMA
 
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)FERMA
 
European Risk Management Seminar 2018 - Cyber Report
European Risk Management Seminar 2018 - Cyber Report European Risk Management Seminar 2018 - Cyber Report
European Risk Management Seminar 2018 - Cyber Report FERMA
 
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018FERMA
 
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPARPreparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPARFERMA
 

More from FERMA (20)

FERMA contribution to the French Presidency agenda
FERMA contribution to the French Presidency agendaFERMA contribution to the French Presidency agenda
FERMA contribution to the French Presidency agenda
 
The role of risk management in corporate resilience
The role of risk management in corporate resilienceThe role of risk management in corporate resilience
The role of risk management in corporate resilience
 
Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience Webinar: the role of risk management in corporate resilience
Webinar: the role of risk management in corporate resilience
 
People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...People, Planet & Performance: sustainability guide for risk and insurance man...
People, Planet & Performance: sustainability guide for risk and insurance man...
 
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
Collaboration of the Year Award winner 2020: Pim Moerman and Rob van den Eijn...
 
Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020Argo Group: operationalizing emerging risk 2020
Argo Group: operationalizing emerging risk 2020
 
Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020Argo Group: entry for emerging risk initiative of the year Award 2020
Argo Group: entry for emerging risk initiative of the year Award 2020
 
George Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland WaterGeorge Ong, Chief Risk Officer, Northern Ireland Water
George Ong, Chief Risk Officer, Northern Ireland Water
 
The European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentationThe European risk manager report 2020: webinar presentation
The European risk manager report 2020: webinar presentation
 
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
GDPR & corporate governance: The Role of Internal Audit and Risk Management O...
 
Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019Facts and figures about our risk management associations in Europe 2019
Facts and figures about our risk management associations in Europe 2019
 
Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?Webinar: how risk management can contribute to sustainable growth?
Webinar: how risk management can contribute to sustainable growth?
 
FERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber SecurityFERMA Webinar: At the Junction of Corporate Governance and Cyber Security
FERMA Webinar: At the Junction of Corporate Governance and Cyber Security
 
Ferma European Risk Manager Report 2018
Ferma European Risk Manager Report 2018Ferma European Risk Manager Report 2018
Ferma European Risk Manager Report 2018
 
Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018Ferma PwC European Risk Manager Report_ full set results 2018
Ferma PwC European Risk Manager Report_ full set results 2018
 
European risk management sustainability seminar report
European risk management sustainability seminar reportEuropean risk management sustainability seminar report
European risk management sustainability seminar report
 
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
Fer008 ferma risk-mangmt_18_sem_sustainabiity_report_v15_07_nov18 (1)
 
European Risk Management Seminar 2018 - Cyber Report
European Risk Management Seminar 2018 - Cyber Report European Risk Management Seminar 2018 - Cyber Report
European Risk Management Seminar 2018 - Cyber Report
 
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
Ferma perspectives #2 - Cyber Risk Governance 09.10.2018
 
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPARPreparing for cyber insurance - FERMA - Insurance Europe - BIPAR
Preparing for cyber insurance - FERMA - Insurance Europe - BIPAR
 

Recently uploaded

Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCRashishs7044
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadAyesha Khan
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menzaictsugar
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Seta Wicaksana
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Servicecallgirls2057
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxMarkAnthonyAurellano
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfJos Voskuil
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Timedelhimodelshub1
 

Recently uploaded (20)

Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in IslamabadIslamabad Escorts | Call 03070433345 | Escort Service in Islamabad
Islamabad Escorts | Call 03070433345 | Escort Service in Islamabad
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
Digital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdfDigital Transformation in the PLM domain - distrib.pdf
Digital Transformation in the PLM domain - distrib.pdf
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Call Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any TimeCall Girls Miyapur 7001305949 all area service COD available Any Time
Call Girls Miyapur 7001305949 all area service COD available Any Time
 

GDPR & corporate Governance, Evaluation after 2 years implementation

  • 1.
  • 2. In partnership with European Risk Manager Report 2020 Edition Top critical threats to the organisation’s growth prospects within the next 12 months CYBER THREAT UNCERTAIN ECONOMIC GROWTH AVAILABILITY OF KEY SKILLS DATA FRAUD OR THEFT OVER-REGULATION CYBER THREAT UNCERTAIN ECONOMIC GROWTH GEOPOLITICAL UNCERTAINLY OVER-REGULATION CHANGING CONSUMER BEHAVIOUR TOP RISK 2020TOP RISK 2018 37% 39% 24% How do you deal with risks arising from emerging technologies ? Identification and assessment of risks prior to adoption of new technologies by the business Identification and assessment of emerging technologies used by the business Analysis and remediation of any insurance coverage gaps
  • 4. Cybersecurity and Data security as top risk again!
  • 5. GDPR :expert’s introduction Ralf Herold Senior Vice President, Corporate Audit BASF Jérôme Avot Group Risk Officer and Data Protection Officer at Faurecia Olivier Micol Head of Data Protection Unit at the European Commission, Directorate- General for Justice
  • 6. GDPR :Expert Talk Olivier Micol Head of Data Protection Unit at the European Commission, Directorate- General for Justice ▪ Key elements of the recent GDPR evaluation report of the European Commission ▪ share the latest data and feedback from companies and civil society ▪ overview of future planned initiatives
  • 7. GDPR :Polling question #1 How would you assess the level of divergence in the enforcement of GDPR regulation by DPA in EU? ❑ High ❑ Medium ❑ Low
  • 8. GDPR :Polling question #2 How do you evaluate your interaction with the DPA in your country? ❑ Very Good ❑ Good ❑ Bad ❑ Very Bad
  • 9. GDPR :Expert Talk ➢ About FAURECIA ➢ Impact of the GDPR on the activities ➢ How to be both DPO and Risk Manager ? ➢ Ongoing challenges ➢ Covid 19 and GDPR Jérôme Avot Group Risk Office and Data Protection Officer, FAURECIA
  • 11. Impact of the GDPR on the activities • While the GDPR was mostly generating fear, uncertainty and doubts before its application in May 2018… the benefits, after more than two years, are widely recognized ! • It forced helped companies to perform a comprehensive inventory of all their data processing activities • … and act on those which were not (fully) compliant (security, data retention, consent…) • It helped to start projects (especially security related) which were not considered as “priority 1”. A new regulation is a good excuse to get budget ☺ • Companies are now taking more care regarding their own sub-contractors (from a legal and practical standpoint) including requirement for certification, audits, … • Most companies are now ready in case of Data Breach, they know how to deal with new “data processing” (privacy by design) and are used to respond to Data Subject Request. • Wider training program to employees regarding data protection contributing to the reinforcement of the overall cyber-security of the company GDPR is a journey, not a destination, but companies have mostly embraced the spirit of GDPR and are moving in the right direction to drastically improve personal data protection.
  • 12. How to be both DPO and Risk Manager ? Being a DPO and Risk Manager is totally compatible… but not all Risk Manager can be DPO and not all DPO could be Risk Manager • The word “Risk” is being mentioned more than 78 times in the official GDPR regulation • Risk Management is one of the pillars of the GDPR Regulation • So who else better than a “Risk Manager” to manage “Personal Data Protection” risk ? • This is not that obvious: • The DPO is usually considered as a “five-legged sheep” : • Need for (even basic) legal knowledge • Need for Information System Security knowledge • Need to be pedagogue, good ability to communicate and train people • Need to have a good internal network and be recognized • Need to be able to assess risks • Not all “Risk Managers” will therefore do the job ☺ • However being both Risk Manager and DPO has many benefits including: • Benefits from “risk oriented” mindset and ensure perfect alignment with Risk Management methodology • Good mix between daily actions as a “DPO” and more medium/long term action as “Risk Manager” • Being able to assess this specific risk at the right level in the overall risk matrix
  • 13. Ongoing challenges ? • Three main ongoing challenges to deal with in the current context: • Ensure continuous GDPR compliance • How to make sure that all new and existing data processing activities are recorded and compliant ? • How to ensure that all changes are being done in compliance with GDPR mindset ? • Spot the weakest link • Security of data is a matter of weakest link and the difficulty is to find out what could be this weakest link leading to a data breach. • How well protected are your test environments ? Does your replicated data are being anonymized ? • Where are your backup stored and how secure they are ? • How well protected is your sub-contractor laptop holding a backup of all your data ? • Deal with the invalidation of the Privacy Shield (since July 2020) • Should we put in place Standard Contractual Clauses (SCCs) or even Binding Corporate Rules (BCRs) ? • Should we start compartmentalizing data in different regions ? (e-mails for instance) • Should we suspend temporarily such transfers until clear guidance is released ?
  • 14. Covid-19 and GPDR During this difficult and complex period, all Europeans DPA are making efforts to provide guidance and assistance to companies on this complex topic… but companies still need to apply GDPR principles and be agile in a fast-paced changing environment ! • Employers have obligations to ensure the health and safety of employees while at work but they also need to ensure compliance with GDPR: A real challenge in this Covid-19 context ! • Health information is classed as “special category of personal data” under GDPR meaning a Data Protection Impact Assessment should be done in order to understand the risks associated with such kind of data processing and… ensure those risks are properly mitigated ! • Typical steps include: • Identify clear needs (“purpose limitation” and “data minimization” principles) for each cases (temperature screening, CCTV, close contacts…) and collect ONLY NECESSARY data • Identity a “Lawful basis of processing” (and forget about consent) • Prepare a “Privacy Policy” (“right to be informed” principle) • Ensure Security and Confidentiality of data (“security” principle) • And… document the measures taken (“accountability” principle)
  • 15. GDPR :Expert Talk ➢ About BASF ➢ Impact of the GDPR on the activities ➢ The role of internal auditors: what has changed? ➢ Ongoing challenges ➢ Covid 19 and GDPR Ralf Herold Senior Vice President, Corporate Audit BASF
  • 16. Facts important to know: Objectives of the EU-GDPR – protection of natural person, and more..! Striving for a balance of all 3 objectives in a common EU-market with same market rules & conditions for all market subjects  protection of personal data is not an absolute right GDPR Recital 1 “protection of natural persons in relation to the processing of personal data Art 1 GDPR & Recital 9 “free flow of personal data throughout the Union” Recital 2 Recital 4 “Economic union, strengthening EU market development” “freedom to conduct business”
  • 17. 17 NationNation Enterprise Enterprise Employee Customer/Vendor 2 3 4 5 6 1 Nation/Government Enterprise/Company 1. Nation/Nation: Contracts & No-Spy 2. Government/Enterprise: Regulatory Business Framework 3. Government/Citizen: Civil Rights/Right to be left alone/Data ownership and disposition rights  National Security & Law Enforcement – “Social Contract: Citizens  Government” 4. Enterprise/Enterprise: Contracts – IP rights – Anti-Trust Regulations 5. Enterprise/Employee: Contracts - Consensus 6. Enterprise/Customer/Vendor: Contracts - Consensus Data Subjects Protection of the Rights of a Natural Person – What Enterprises can do and have to focus on ➢ Enterprises adhere to rules ➢ Can‘t solve political disputes or Nations or Government affairs
  • 18. BASF SE = Main Establishment BASF Group EU-Companies = Group Of Undertakings Lead Supervisory Authority The State Commissioner for Data Protection and the Freedom of Information Rhineland-Palatinate LfDI RLP Data Protection Commissioner by Country Consistency Mechanism BASF applies the One-Stop-Shop Concept (Art. 56 & Art. 60 GDPR) Data Protection @ BASF ➢ by design Europa ➢ de facto Global
  • 22. About FERMA FERMA brings together 22 risk management associations in 21 European countries. They represent nearly 5,000 professional risk managers active in a wide range of business sectors. The Federation of European Risk Management Associations (FERMA) speaks for the risk management profession in Europe. FERMA acts on its behalf at European level and promotes the risk management profession. FERMA provides a risk management perspective on European issues and strengthens the profession through a European risk management certification (rimap). www.ferma.eu
  • 23. About ECIIA ECIIA gives voice to 48.000 Internal Auditors in 34 countries from wider Europe. The European Confederation of Institutes of Internal Auditing (ECIIA) is the voice of internal audit in Europe. Our role is to enhance corporate governance through the promotion of the professional practice of internal auditing. The ECIIA mission is to further the development of good corporate governance and internal audit at the European level, through • Knowledge sharing • Developing key relationships • Impacting the regulatory environment, by dealing with the European Union, its Parliament and the European Authorities.