SlideShare a Scribd company logo
Marjane Moghimi
uk.marjanem@gmail.com
GDPR - time for action
November 2017
Soft or hard Brexit, GDPR is coming into force on 25 May
2018 and firms need to prepare…
Marjane Moghimi Nov 2017
The Queen’s Speech has confirmed that the General Data Protection
Regulation will form part of UK law following the country’s withdrawal from
the European Union. The Speech noted that “Over 70% of all trade in
services are enabled by data flows, meaning that data protection is critical
to international trade.” 22 June 2017
And after Brexit ?
Marjane Moghimi Nov 2017
• On 21 June 2017 the UK Government revealed its legislative programme for the
coming two years. As well as pressing ahead with the UK’s withdrawal from the
European Union, the Government has confirmed its intention to bring the EU
General Data Protection Regulation (the “GDPR”) into UK law, ensuring the
country’s data protection framework is “suitable for our new digital age, allowing
citizens to better control their data.”
• Therefore it seems that the after Brexit rules will be compatible and aligned with
the EU GDPR.
► But some of the EU based clients may ask for the localisation of databases in EU.
► So where the data (server, data centre, cloud) is stored needs some reflexion.
UK
Marjane Moghimi Nov 2017
UK Current
• Current legislation
• DPA 1998
25 May 2018
• Future legislation
• GDPR
Map
• Cross Map the change from current law to new regulation
• Will give you the picture of ‘As is’ and ‘To Be’
GDPR overview
Marjane Moghimi Nov 2017
Data
Controller
Data
Processor
Data
Subject
Aim is to protect a natural
person living in the EU
(include EEA) by expanding
the definition of personal
data and giving more
rights to privacy
Impose new duties
and obligation on
Initial assessment
• Data Controller
– Is in direct contact with Data
Subject
– It is ultimately responsible for
the application of Data
Protection principals
– Must provide privacy notice
when collecting data
– Must inform the data subject in
case of data breach
• Data Processor
– Has direct responsibility under
GDPR
– Must assure the security of
processing operations,
– Must name a Data Protection
Officer,
– Must notify any breach of data
protection obligations to the
Data Controller.
Marjane Moghimi Nov 2017
New rights of Data Subject
• The aim is to give to Data Subject the ownership of their own data
• the data subjects' rights :
– right to be informed,
– right to object to the accuracy of the information
– right of access (free)
– right to be forgotten (exceptions do exist)
– right to give consent and withdraw it easily
– The consents need to specific for each usage of data
– Right to be informed if a data breach occurred without undue delay
– Etc.
Marjane Moghimi Nov 2017
What is the new definition of Personal Data ?
• The GDPR broadens the definition of “personal data.”
• Sensitive data such as biometric and genetic data will be subject to a
higher standard.
• Under the terms of GDPR, personal data refers to anything that could be
used to identify an individual, such as :
– name,
– email address,
– IP address,
– social media profiles
– Phone numbers
– Social security numbers
– Etc.
Marjane Moghimi Nov 2017
GDPR for HR
• Your past, current and future employees are Data Subject
• Under GDPR they have extended rights such as: right to rectification and erasure, right of
portability of their data and subject access request (without fee )
• Action points, data audit:
– What data you have?
– Where it is located?
– Why such data is collected? Is it up to date?
– To and From where is transferred (in the company, outside 1/3 parties, outside EU and
EEA)? Which data points are transferred?
– How long is kept?
– On which basis ? Legitimate business ? If not erase.
– Consents need to be reviewed
►Data mapping and flow charts help to have a global view of the flow of Data from and into
various systems
►A gap analysis will highlight areas of concern you need to look at.
Marjane Moghimi Nov 2017
Data audit
What Staff data
do you have
Where is come
from?
Where /How is
stored?
What happens
with it in your
organization?
When/How is
it deleted?
Is it up to date?
It is transferred
outside the
firm?
Identify the
Stakeholders
HR
Finance
Payroll
Third parties
Etc.
Marjane Moghimi Nov 2017
Expand on each point
till you have a clear
picture and cover it
completely
Personal Data mapping -1
Why a firm is
processing
personal data?
1- Staff administration
2- Client administration
3- For safety and security
4- To meet legal obligation
5- To provide service to 1/3 parties
6- To improve services/businesses
7- For direct marketing
8- Etc.
Marjane Moghimi Nov 2017
Personal Data mapping -2
For each reason
defined, you
need to precise
each activities
that it covers
1- Staff administration
Recruitment (recruitment agency, reference etc.)
Payroll
Benefit (pension, private medical health, insurance etc.)
Appraisal
Record of attendance, leave, holidays
Correspondence related to the employment
Etc.
Marjane Moghimi Nov 2017
Personal Data mapping -3
Then define
each category,
sub category of
data you collect
Examples:
Job candidates
Current staff/contractors
Former staff/contractors
Emergency contact/relatives
Third party benefit providers
Contacts at suppliers
Etc.
Marjane Moghimi Nov 2017
Action list for compliance with GDPR
After the Data mapping:
1. Run a GDPR compliance gap
– Run a review of all of your data entries ( online, 1/3 parties etc.)
– Analysis of your operations, IT, processes, systems, procedures
• Data flow (in, out, from, to)
• Vendors and 1/3 parties data review
2. Create a GDPR Risk Register
3. Define areas for change: Processes, People, Technology
– Prioritize work according to the Risk Register
– Plan communication with data subject (consents, breach notification)
– Update your data protection compliance procedures
– Keep an audit trail of all your activities in order to comply with the regulation
4. Highlight and act on areas overlapping with other regulations (if applicable to
your industry)
Marjane Moghimi Nov 2017
People, processes, technology
Marjane Moghimi Nov 2017
Certification
• GDPR recommend certification schemes
Certification is voluntary. Currently there is no official certification body for GDPR
• ISO 27001 is such certification
– Is an information security management standard
– Follow international best practices
– Focus on information security (firms and their customers)
– Based on formal risk assessment
– 3 aspects to information security
• People
• Processes
• Technology
– Data protection arrangements and processes are similar to GDPR
recommendation
– It can be used as a reference on complying with GDPR regulation
Marjane Moghimi Nov 2017
We already comply with DPA 1998, what more should we do?
• Cross-map GDPR to DPA 1998:
– Focus your action to area of changes
• If you choose to apply ISO 27001:
– Cross-map GDPR to DPA 1998 and ISO 27001
– Highlight areas of changes
– Highlight high risk areas
– Prioritize the work on the most sensitive areas
• Change Management needs to cover
– People
– IT
– Processes and Procedures
– Training for staff
– Communication about GDPR and raising awareness about data security
Marjane Moghimi Nov 2017
GDPR in others European countries
If you have activities in EU you need to be aware of local GDPR application:
• France : CNIL is in forefront of GDPR application
– https://www.cnil.fr/
– https://www.cnil.fr/fr/node/15798
• Luxembourg
– https://cnpd.public.lu/en.html
• Offshore Isle of Man, Jersey, Guernsey (Third Country) have secured a Adequacy
status
– http://ec.europa.eu/justice/data-protection/international-
transfers/adequacy/index_en.htm
Marjane Moghimi Nov 2017
GDPR in Financial industry
• GDPR is overlapping with other regulation such as MIFID 2, PRIIPS, PSD2
• Firms need to separate 3 sort of data:
– Employees, professionals clients, non professional clients (under the definition
of MIFID 2)
• Personal data of employees
• Personal Data of professional clients and Non professional clients
• Personal Data of retail clients
• Interactions between various IT systems (backups systems are in the loop too)
• While banks and other financial firms are familiar with various regulations,
adhering to GDPR requires the collection of large amounts of customer data,
which is then collated and used for various activities, such as client on-boarding,
KYC, relationship management, trade-booking, accounting, etc.
• During these processes, customer data is exposed to a large number of different
people, systems at different stages, and this is the challenge.
Marjane Moghimi Nov 2017
Regulation Overlap: MIFID II and GDPR
MIFID II (3 Jan 2018)
• RTS 4 and ESMA Q&A Oct 2017:
The requirement to identify the clients and
clients of clients in transaction and position
reporting can not be waived.
• For natural persons, the important
identifiers are: passport number and
CONCAT code combining nationality, first
name and surname of position holder.
• If a person is used, that person must be
identified by their ID number, passport
number, tax or national insurance number,
depending on their nationality.
• In the absence of this information, a
concatenated code can be used consisting
of date of birth, the first five characters of
first name and the first five characters of
surname.
GDPR (25 May 2018)
• Under GDPR investments firms are Data
Controller.
• Under MIFID II they are required to report
disaggregated (i.e. Client, Client of Client
etc.) reports.
• Firms need to take steps to ensure that
the data they report is accurate, and that
appropriate consent is obtained to using
individual’s data as part of transaction
reporting, in a way that meets data
protection requirements.
• The safety, security and confidentiality of
clients information stay with the
investments firms
Marjane Moghimi Nov 2017
Regulation Overlap: MIFID II and GDPR
MIFID II
The name and date of birth in both side
of the trade are mandatory part of trade,
transaction and position reporting duties
• Buyer
• Buyer Decision Maker
• Seller
• Seller Decision Maker
GDPR
• Employees information are held in HR
database
• Counterparties information in
Counterparty Data base.
• Clients information in Client database
►You need to have specific consent from those data subject concerned by MIFID II
►Consents from all 1/3 parties are necessary if you have a legitimate interest in
collecting their data
Marjane Moghimi Nov 2017
e-privacy
• Is a Regulation coming into force the same date as GDPR
• Will replace the current Directive
• Its aim is high level of privacy and data protection
• The new regulation will bring significant changes:
– concern to all providers of electronic communication services
• Include Facebook Messenger, Whatsapp, etc.
– will apply to content and meta data
– Simpler rules regarding cookies and spam
– Needs for specific and free consents ; which can easily withdraw.
– Put the emphasis on confidentiality of electronic communications data
including while in transit and cover storage providers (including ’cloud’)
• The regulation is still not finalised so some changes may come into light later.
Marjane Moghimi Nov 2017
Reference
• Text:
– http://ec.europa.eu/justice/data-protection/individuals/index_en.htm
– https://gdpr-info.eu
– ec.europa.eu/justice/ data-protection/reform/ files/regulation_oj_en.pdf
• Summary: www.eugdpr.org/article-summaries.html
• FAQs: www.eugdpr.org/gdpr-faqs.html
• E-privacy: https://edps.europa.eu/sites/edp/files/publication/17-10-
05_edps_recommendations_on_ep_amendments_en.pdf
Marjane Moghimi Nov 2017

More Related Content

What's hot

Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?
IT Governance Ltd
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPR
IT Governance Ltd
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
Nordic APIs
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
IBB Law
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
Craig Clark ITIL, CIS LI,EU GDPR P
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPR
IT Governance Ltd
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
BCC - Solutions for IBM Collaboration Software
 
Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Mark Honeyball
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Qualsys Ltd
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
Frederick Penaud
 
GDPR training
GDPR training GDPR training
GDPR training
ASL
 
GDPR in practice
GDPR in practiceGDPR in practice
GDPR in practice
ZoneFox
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
Harrison Clark Rickerbys
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
KeithBudden3
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...
IT Governance Ltd
 
GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?
Sage HR
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
IISPEastMids
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
WhitmeyerTuffin
 

What's hot (20)

Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?Accountability under the GDPR: What does it mean for Boards & Senior Management?
Accountability under the GDPR: What does it mean for Boards & Senior Management?
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
Appointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPRAppointing a Data Protection Officer under the GDPR
Appointing a Data Protection Officer under the GDPR
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPR
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
 
Datum DPO outsourced May 2016
Datum DPO outsourced May 2016Datum DPO outsourced May 2016
Datum DPO outsourced May 2016
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
GDPR training
GDPR training GDPR training
GDPR training
 
GDPR in practice
GDPR in practiceGDPR in practice
GDPR in practice
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...NY State's cybersecurity legislation requirements for risk management, securi...
NY State's cybersecurity legislation requirements for risk management, securi...
 
GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?GDPR - are you ready for the challenge?
GDPR - are you ready for the challenge?
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 

Similar to GDPR will be the new regulation on may 2018

The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
Case IQ
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
RAKESH S
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
Ulf Mattsson
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
Jean-Michel Tyszka
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
IT Governance Ltd
 
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
Mailjet
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacy
GuyVanderSande
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Bart Van Den Brande
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
Aaron Banham
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
Tech Trust
 
MIFID II and GDPR
MIFID II and GDPR MIFID II and GDPR
MIFID II and GDPR
Marjane Moghimi, ERP
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
CIO Edge
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
Srijan Technologies
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
IT Governance Ltd
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
Omo Osagiede
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
Employee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdfEmployee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdf
Andrey Prozorov, CISM, CIPP/E, CDPSE. LA 27001
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
Extentia Information Technology
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
Guy Griffiths
 

Similar to GDPR will be the new regulation on may 2018 (20)

The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
 
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
How to Work With 3rd Party Software Providers Under GDPR - A Digital Marketin...
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacy
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
MIFID II and GDPR
MIFID II and GDPR MIFID II and GDPR
MIFID II and GDPR
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Employee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdfEmployee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdf
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 

Recently uploaded

一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
oz8q3jxlp
 
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
v3tuleee
 
Q1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year ReboundQ1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year Rebound
Oppotus
 
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
pchutichetpong
 
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
Tiktokethiodaily
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP
 
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
ukgaet
 
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdfCh03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
haila53
 
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
u86oixdj
 
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
yhkoc
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
ewymefz
 
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
axoqas
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
enxupq
 
Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
Opendatabay
 
一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单
ocavb
 
Machine learning and optimization techniques for electrical drives.pptx
Machine learning and optimization techniques for electrical drives.pptxMachine learning and optimization techniques for electrical drives.pptx
Machine learning and optimization techniques for electrical drives.pptx
balafet
 
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
slg6lamcq
 
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdfSample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Linda486226
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
nscud
 
一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理
一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理
一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理
mbawufebxi
 

Recently uploaded (20)

一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
一比一原版(Deakin毕业证书)迪肯大学毕业证如何办理
 
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理一比一原版(UofS毕业证书)萨省大学毕业证如何办理
一比一原版(UofS毕业证书)萨省大学毕业证如何办理
 
Q1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year ReboundQ1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year Rebound
 
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
 
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
1.Seydhcuxhxyxhccuuxuxyxyxmisolids 2019.pptx
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
 
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
 
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdfCh03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
 
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
原版制作(Deakin毕业证书)迪肯大学毕业证学位证一模一样
 
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
一比一原版(CU毕业证)卡尔顿大学毕业证成绩单
 
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
一比一原版(IIT毕业证)伊利诺伊理工大学毕业证成绩单
 
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
 
Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
 
一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单一比一原版(TWU毕业证)西三一大学毕业证成绩单
一比一原版(TWU毕业证)西三一大学毕业证成绩单
 
Machine learning and optimization techniques for electrical drives.pptx
Machine learning and optimization techniques for electrical drives.pptxMachine learning and optimization techniques for electrical drives.pptx
Machine learning and optimization techniques for electrical drives.pptx
 
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
一比一原版(UniSA毕业证书)南澳大学毕业证如何办理
 
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdfSample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
 
一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理
一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理
一比一原版(Bradford毕业证书)布拉德福德大学毕业证如何办理
 

GDPR will be the new regulation on may 2018

  • 1. Marjane Moghimi uk.marjanem@gmail.com GDPR - time for action November 2017
  • 2. Soft or hard Brexit, GDPR is coming into force on 25 May 2018 and firms need to prepare… Marjane Moghimi Nov 2017 The Queen’s Speech has confirmed that the General Data Protection Regulation will form part of UK law following the country’s withdrawal from the European Union. The Speech noted that “Over 70% of all trade in services are enabled by data flows, meaning that data protection is critical to international trade.” 22 June 2017
  • 3. And after Brexit ? Marjane Moghimi Nov 2017 • On 21 June 2017 the UK Government revealed its legislative programme for the coming two years. As well as pressing ahead with the UK’s withdrawal from the European Union, the Government has confirmed its intention to bring the EU General Data Protection Regulation (the “GDPR”) into UK law, ensuring the country’s data protection framework is “suitable for our new digital age, allowing citizens to better control their data.” • Therefore it seems that the after Brexit rules will be compatible and aligned with the EU GDPR. ► But some of the EU based clients may ask for the localisation of databases in EU. ► So where the data (server, data centre, cloud) is stored needs some reflexion.
  • 4. UK Marjane Moghimi Nov 2017 UK Current • Current legislation • DPA 1998 25 May 2018 • Future legislation • GDPR Map • Cross Map the change from current law to new regulation • Will give you the picture of ‘As is’ and ‘To Be’
  • 5. GDPR overview Marjane Moghimi Nov 2017 Data Controller Data Processor Data Subject Aim is to protect a natural person living in the EU (include EEA) by expanding the definition of personal data and giving more rights to privacy Impose new duties and obligation on
  • 6. Initial assessment • Data Controller – Is in direct contact with Data Subject – It is ultimately responsible for the application of Data Protection principals – Must provide privacy notice when collecting data – Must inform the data subject in case of data breach • Data Processor – Has direct responsibility under GDPR – Must assure the security of processing operations, – Must name a Data Protection Officer, – Must notify any breach of data protection obligations to the Data Controller. Marjane Moghimi Nov 2017
  • 7. New rights of Data Subject • The aim is to give to Data Subject the ownership of their own data • the data subjects' rights : – right to be informed, – right to object to the accuracy of the information – right of access (free) – right to be forgotten (exceptions do exist) – right to give consent and withdraw it easily – The consents need to specific for each usage of data – Right to be informed if a data breach occurred without undue delay – Etc. Marjane Moghimi Nov 2017
  • 8. What is the new definition of Personal Data ? • The GDPR broadens the definition of “personal data.” • Sensitive data such as biometric and genetic data will be subject to a higher standard. • Under the terms of GDPR, personal data refers to anything that could be used to identify an individual, such as : – name, – email address, – IP address, – social media profiles – Phone numbers – Social security numbers – Etc. Marjane Moghimi Nov 2017
  • 9. GDPR for HR • Your past, current and future employees are Data Subject • Under GDPR they have extended rights such as: right to rectification and erasure, right of portability of their data and subject access request (without fee ) • Action points, data audit: – What data you have? – Where it is located? – Why such data is collected? Is it up to date? – To and From where is transferred (in the company, outside 1/3 parties, outside EU and EEA)? Which data points are transferred? – How long is kept? – On which basis ? Legitimate business ? If not erase. – Consents need to be reviewed ►Data mapping and flow charts help to have a global view of the flow of Data from and into various systems ►A gap analysis will highlight areas of concern you need to look at. Marjane Moghimi Nov 2017
  • 10. Data audit What Staff data do you have Where is come from? Where /How is stored? What happens with it in your organization? When/How is it deleted? Is it up to date? It is transferred outside the firm? Identify the Stakeholders HR Finance Payroll Third parties Etc. Marjane Moghimi Nov 2017 Expand on each point till you have a clear picture and cover it completely
  • 11. Personal Data mapping -1 Why a firm is processing personal data? 1- Staff administration 2- Client administration 3- For safety and security 4- To meet legal obligation 5- To provide service to 1/3 parties 6- To improve services/businesses 7- For direct marketing 8- Etc. Marjane Moghimi Nov 2017
  • 12. Personal Data mapping -2 For each reason defined, you need to precise each activities that it covers 1- Staff administration Recruitment (recruitment agency, reference etc.) Payroll Benefit (pension, private medical health, insurance etc.) Appraisal Record of attendance, leave, holidays Correspondence related to the employment Etc. Marjane Moghimi Nov 2017
  • 13. Personal Data mapping -3 Then define each category, sub category of data you collect Examples: Job candidates Current staff/contractors Former staff/contractors Emergency contact/relatives Third party benefit providers Contacts at suppliers Etc. Marjane Moghimi Nov 2017
  • 14. Action list for compliance with GDPR After the Data mapping: 1. Run a GDPR compliance gap – Run a review of all of your data entries ( online, 1/3 parties etc.) – Analysis of your operations, IT, processes, systems, procedures • Data flow (in, out, from, to) • Vendors and 1/3 parties data review 2. Create a GDPR Risk Register 3. Define areas for change: Processes, People, Technology – Prioritize work according to the Risk Register – Plan communication with data subject (consents, breach notification) – Update your data protection compliance procedures – Keep an audit trail of all your activities in order to comply with the regulation 4. Highlight and act on areas overlapping with other regulations (if applicable to your industry) Marjane Moghimi Nov 2017
  • 16. Certification • GDPR recommend certification schemes Certification is voluntary. Currently there is no official certification body for GDPR • ISO 27001 is such certification – Is an information security management standard – Follow international best practices – Focus on information security (firms and their customers) – Based on formal risk assessment – 3 aspects to information security • People • Processes • Technology – Data protection arrangements and processes are similar to GDPR recommendation – It can be used as a reference on complying with GDPR regulation Marjane Moghimi Nov 2017
  • 17. We already comply with DPA 1998, what more should we do? • Cross-map GDPR to DPA 1998: – Focus your action to area of changes • If you choose to apply ISO 27001: – Cross-map GDPR to DPA 1998 and ISO 27001 – Highlight areas of changes – Highlight high risk areas – Prioritize the work on the most sensitive areas • Change Management needs to cover – People – IT – Processes and Procedures – Training for staff – Communication about GDPR and raising awareness about data security Marjane Moghimi Nov 2017
  • 18. GDPR in others European countries If you have activities in EU you need to be aware of local GDPR application: • France : CNIL is in forefront of GDPR application – https://www.cnil.fr/ – https://www.cnil.fr/fr/node/15798 • Luxembourg – https://cnpd.public.lu/en.html • Offshore Isle of Man, Jersey, Guernsey (Third Country) have secured a Adequacy status – http://ec.europa.eu/justice/data-protection/international- transfers/adequacy/index_en.htm Marjane Moghimi Nov 2017
  • 19. GDPR in Financial industry • GDPR is overlapping with other regulation such as MIFID 2, PRIIPS, PSD2 • Firms need to separate 3 sort of data: – Employees, professionals clients, non professional clients (under the definition of MIFID 2) • Personal data of employees • Personal Data of professional clients and Non professional clients • Personal Data of retail clients • Interactions between various IT systems (backups systems are in the loop too) • While banks and other financial firms are familiar with various regulations, adhering to GDPR requires the collection of large amounts of customer data, which is then collated and used for various activities, such as client on-boarding, KYC, relationship management, trade-booking, accounting, etc. • During these processes, customer data is exposed to a large number of different people, systems at different stages, and this is the challenge. Marjane Moghimi Nov 2017
  • 20. Regulation Overlap: MIFID II and GDPR MIFID II (3 Jan 2018) • RTS 4 and ESMA Q&A Oct 2017: The requirement to identify the clients and clients of clients in transaction and position reporting can not be waived. • For natural persons, the important identifiers are: passport number and CONCAT code combining nationality, first name and surname of position holder. • If a person is used, that person must be identified by their ID number, passport number, tax or national insurance number, depending on their nationality. • In the absence of this information, a concatenated code can be used consisting of date of birth, the first five characters of first name and the first five characters of surname. GDPR (25 May 2018) • Under GDPR investments firms are Data Controller. • Under MIFID II they are required to report disaggregated (i.e. Client, Client of Client etc.) reports. • Firms need to take steps to ensure that the data they report is accurate, and that appropriate consent is obtained to using individual’s data as part of transaction reporting, in a way that meets data protection requirements. • The safety, security and confidentiality of clients information stay with the investments firms Marjane Moghimi Nov 2017
  • 21. Regulation Overlap: MIFID II and GDPR MIFID II The name and date of birth in both side of the trade are mandatory part of trade, transaction and position reporting duties • Buyer • Buyer Decision Maker • Seller • Seller Decision Maker GDPR • Employees information are held in HR database • Counterparties information in Counterparty Data base. • Clients information in Client database ►You need to have specific consent from those data subject concerned by MIFID II ►Consents from all 1/3 parties are necessary if you have a legitimate interest in collecting their data Marjane Moghimi Nov 2017
  • 22. e-privacy • Is a Regulation coming into force the same date as GDPR • Will replace the current Directive • Its aim is high level of privacy and data protection • The new regulation will bring significant changes: – concern to all providers of electronic communication services • Include Facebook Messenger, Whatsapp, etc. – will apply to content and meta data – Simpler rules regarding cookies and spam – Needs for specific and free consents ; which can easily withdraw. – Put the emphasis on confidentiality of electronic communications data including while in transit and cover storage providers (including ’cloud’) • The regulation is still not finalised so some changes may come into light later. Marjane Moghimi Nov 2017
  • 23. Reference • Text: – http://ec.europa.eu/justice/data-protection/individuals/index_en.htm – https://gdpr-info.eu – ec.europa.eu/justice/ data-protection/reform/ files/regulation_oj_en.pdf • Summary: www.eugdpr.org/article-summaries.html • FAQs: www.eugdpr.org/gdpr-faqs.html • E-privacy: https://edps.europa.eu/sites/edp/files/publication/17-10- 05_edps_recommendations_on_ep_amendments_en.pdf Marjane Moghimi Nov 2017