SlideShare a Scribd company logo
1 of 59
Download to read offline
How to implement GDPR in the document repository
Xenit - December, 11 2017
December, 5 2017
4 pm - 5 pm CET
Agenda
• CDI-Partners Testimonial: GDPR Principles [15 min]
• Alfresco Testimonial: How Alfresco can help your
organization comply with the GDPR [15 min]
• Xenit Testimonial: A managed shared drive [15 min]
• Top tips to start preparing for the GDPR [5 min]
• Xenit Use Case [5 min]
• Q&A session [5 min]
How to implement GDPR in the
document repository
CDI-Partners
GDPR Principles
www.xenit.eu
Bart Van Bouwel – Managing Partner
CDI-Partners
GDPR Principles
Bart Van Bouwel – Managing Partner
CDI-Partners Testimonial
Bart Van Bouwel – Managing Partner - CDI-Partners
“Did you know that most data breaches reported are related to
unstructured data? Documents, spreadsheets, mails and even
paper files? Without a clear focus on documents, companies
can’t claim adequate protection of personal data.”
How to implement GDPR in the document repository
Bart Van Bouwel
bart.van.bouwel@cdi-partners.be
General Data Protecting Regulation
Purpose
Give individuals control over their personal data
Applies to
All companies that process personal data of EU citizens
European Regulation
One law across the EU, enforced as of May 25th, 2018
Some Principles
Lawfully, fairly and transparent
Collected for specified, explicit and legitimate purposes
Adequate, relevant and limited  Data Minimization
Processing must be
Consult, correct, request deletion, portability of their personal data
Rights of Data Subjects
Privacy by design – Privacy by default
Data Breach notification is mandatory
Fines
Up to € 20.000.000 or 4 % of total worldwide annual turnover
Proportional to the scale of the infringements
Other measures possible
Issue warnings and reprimands
Order to comply with the data subject's requests
Order to bring processing operations into compliance
Order to communicate a personal data breach to the data subject
Impose a temporary or definitive limitation including a ban on processing
…
Personal Data
Home & work information
Health information
Finger print &
Genetic information
Family & demographic
information
Online behaviour & shopping information
Union membership
Political opinions
Religion & Race
Information relating to an identified or identifiable natural person
Personal data can be structured (databases) or unstructured (documents, listings, reports, spreadsheets, …)
Stored in databases
Accessed through applications
More control  More easy to protect
Structured data
In documents and files
Stored on local or network drives / Cloud / USB Keys / …
Easily copied and distributed
Less control  More difficult to protect
Unstructured data
Structured data or Unstructured data?
Where to start?
Where to focus
GDPR in practice
No GDPR examples available
Based upon EU Data Protection Directive 1995
Data breach notification is a best practice
Maximum fine £ 500.000
Data Protection Act 1998 (UK)
Information available about breaches and sanctions
ICO – Information Commissioners’ Office
Examples of Data Breaches
Data Protection Act - Source: ICO (January – March 2017) – 678 breaches
Loss/theft of paperwork
13%
Unauthorised or unlawful
processing
21%
Data posted/faxed
incorrect recipient
11%Data emailed to incorrect
recipient
11%
Cyber incident
14%
Failure to redact data
7%
Failure to use bcc
5%
Data left in insecure
location
4%
Other
9%
Loss/theft of unencrypted device
4% Verbal Disclosure
1%
Document related
>50% related to documents
Fines by ICO
Marketing
42%
Process
30%
Theft
(employee)
19%
IT - Security
9%
Categories of Fines
Data Protection Act - Source: ICO (January – September 2017)
• 42% Marketing
 Mostly deliberate actions with positive ROI
• Biggest risk are found in the 58%
• Some examples
– Sensitive data lost in the mail
– Employees accessing or stealing sensitive data
– A cyber attack stealing 30.000 emails
– Leaving paper files in a cabinet that was sold
– A laptop containing sensitive documents that was stolen
– Backing up sensitive documents to a free cloud storage
• All these fines where given for breaches relating to
unstructured data
• Most breaches and almost all cases that are fined are
from undeliberate or deliberate acts from within the
company
Conclusion
• Fines will be given after someone files a complaint
– Focus on solutions to prevent data breaches
• Start with
– Processes related to rights of individuals
• Privacy statements / proof of consent / demands to access – correct – erase data
– Unstructured data
• What functionalities do you need for your documents?
Challenges for unstructured data
1. Identify documents containing personal data and label them appropriately
2. State of the art security of the documents and the metadata
3. Monitor and control access to the documents, store metadata to prove legitimate
purpose
4. Make documents available offline in a secure way
5. Detect breaches
6. Keep track of the right time to delete documents and permanently delete the
documents so no backup copies exist
7. Control the usage of documents by external parties
CDI-Partners
GDPR Principles
www.xenit.eu
Bart Van Bouwel – Managing Partner
Alfresco
How the Alfresco Digital Business Platform can help your company comply with GDPR
George Parapadakis – Director, Business Solutions Strategy - EMEA
Alfresco Testimonial
George Parapadakis – Business Solutions Strategy - Alfresco
“GDPR will touch every department, every function
and every operation inside your organization. It will
not only change the way you manage information, it
will change the way people behave.”
The Alfresco
Digital Business Platform for
George Parapadakis
November 2017
Over 24 GDPR Articles we can help with…
• Lawful Processing, Minimisation, Consent, PII detection
• Right of Access
• Right to Correct data (Rectification)
• Right to be Forgotten (Erasure)
• Right to Data Portability
• Right to Object / Withdraw consent
• Data Protection and Security (Pseudonymisation)
• Keeping Records of Processing
• Report Data Breaches
• Data Protection Impact Assessments
• 3rd Party Notification
• Automated Decision Making
• Policy Management
• Certification
• Data Residency
Article 15
Article 16
Article 20
Article 25, 32
Article 7, 18, 21
Article 30
Article 17
Article 5, 6, 7, 9
Article 19
Article 40
Article 45, 46
Article 42
Article 33, 34
Article 35, 36
Article 22
Alfresco Digital Business Platform
Application Development Framework
Alfresco Process
Services
Alfresco Content
Services
Integrations / Extensions
Open APIs and Open Standards
On-Prem, Cloud, Hybrid, Managed
Intelligence and Analytics
Alfresco Governance Services
Alfresco Digital Business Platform
Application Development Framework
Alfresco Process
Services
Alfresco Content
Services
Integrations / Extensions
Open APIs and Open Standards
On-Prem, Cloud, Hybrid, Managed
Intelligence and Analytics
Alfresco Governance Services
Alfresco
GDPR
Framework
Managing Policies & Certify Users
policy authoring, review, approval, distribution and
sign-off (ACS)
Identify, protect and manage GDPR sensitive
content
metadata and aspects to create a GDPR Asset
Register (ACS)
Classification Marks to secure access to PII (AGS)
Execute disposition policies (AGS)
Manage GDPR related processes
Define and execute Subject Access Requests, data
portability, erasure, etc. (APS)
Manage Breach Notifications and Impact
assessments (APS)
Compliance & Audit Reporting
Policy Management
6
Capture Audit Trail
Policy
Template
Collaborative
Authoring
Author
Author
Author
Author
Revise
Approve & Certificate
Alfresco
GDPR
Framework
Managing Policies & Certify Users
policy authoring, review, approval, distribution and
sign-off (ACS)
Identify, protect and manage GDPR sensitive
content
metadata and aspects to create a GDPR Asset
Register (ACS)
Classification Marks to secure access to PII (AGS)
Execute disposition policies (AGS)
Manage GDPR related processes
Define and execute Subject Access Requests, data
portability, erasure, etc. (APS)
Manage Breach Notifications and Impact
assessments (APS)
Compliance & Audit Reporting
GDPR Asset Register
Security Marks
Finance
Legal
Marketing
HR
Group A
Audit Trail
…..
Redacted /
Pseudonymised
Alfresco
GDPR
Framework
Managing Policies & Certify Users
policy authoring, review, approval, distribution and
sign-off (ACS)
Identify, protect and manage GDPR sensitive
content
metadata and aspects to create a GDPR Asset
Register (ACS)
Classification Marks to secure access to PII (AGS)
Execute disposition policies (AGS)
Manage GDPR related processes
Define and execute Subject Access Requests, data
portability, erasure, etc. (APS)
Manage Breach Notifications and Impact
assessments (APS)
Compliance & Audit Reporting
Subject Access Request
Capture Audit Trail
Amend
Systems
Collect
Data
Notify
3rd
parties
Withdraw
Consent
Assemble
Output
Prepare
Response
Review
Response
Respond to
Customer
Capture
Audit Trail
TriageValidate
Request
Amendments
Consent
Withdrawal
Data Portability
Erasure
Email
Phone
Letter
In Person
Internal ACS
File System
LoB Integration
External Process
External ECM
Cloud EFSS
Manual
Alfresco
GDPR
Framework
Managing Policies & Certify Users
policy authoring, review, approval, distribution and
sign-off (ACS)
Identify, protect and manage GDPR sensitive
content
metadata and aspects to create a GDPR Asset
Register (ACS)
Classification Marks to secure access to PII (AGS)
Execute disposition policies (AGS)
Manage GDPR related processes
Define and execute Subject Access Requests, data
portability, erasure, etc. (APS)
Manage Breach Notifications and Impact
assessments (APS)
Compliance & Audit Reporting
Typical GDPR Reports
Asset Register
SAR Dashboard
Record of Processing
Certification
Impact Assessments
Policy Impact List, by law
Digital Business Platform
=
“Data Privacy By Design”
ü Secure place for GDPR information & metadata
ü Maximise automation to enforce compliance controls
ü Proactively collect audit trails & evidence
For more information:
Alfresco.com/gdpr
George.Parapadakis@Alfresco.com
CDI-Partners
GDPR Principles
www.xenit.eu
Bart Van Bouwel – Managing Partner
Xenit
Alfred GDPR Approach
Ronny Timmermans – CEO and Managing Director
Xenit Testimonial
Ronny Timmermans – CEO, Managing Director - Xenit
“Governance has always been a concern of Xenit and a particular strength of
Alfresco. GDPR makes us more aware that data are valuable assets, with
privacy and sensitivity implications for every individual we interact with in our
corporate environment. Building upon the enterprise capabilities of Alfresco
and leveraging our Alfred products, data protection comes by design and not
as an afterthought. ”
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu 9
GDPR DATA CLASSIFICATION
PERSONAL DATA
[Cat 1]
a name, an identification number, location
data, an online identifier or to one or more
factors specific to the physical, economic,
cultural or social identity
SENSITIVE INFORMATION
[Cat 2]
on racial or ethnic origin, political
opinions, religious or philosophical beliefs,
or trade union membership, and the
processing of genetic data, biometric data
SENSITIVE DATA
[Cat 3]
Relating to criminal
convictions and offences
DATA PROCESSING MANDATE
• A private company can claim legitimate interest to process Cat 1
• Consent to process Sensitive information
• Cat 3 can be processed under the control of an Official Authority
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Alfred Protection Principles
Protection Principle 1
Unless you know the key (name, other id) you
cannot retrieve information about a person.
Protection Principle 2
Only when you have the appropriate role, you
can view and consult Cat1, Cat2 and Cat3 data
in the user interface.
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.euwww.xenit.eu
Alfred GDPR package
• Build upon Alfresco ACS, can be enriched with:
• Alfresco Process Services
• Alfresco Governance Services
• Alfred GDPR contains:
• GDPR edition of Alfred Desktop and Alfred Finder
• Alfred Edge with audit, query control and GDPR
access rules
• Alfred GDPR Model and Behaviour
• Option Module: Alfred GDPR Detect PII
www.xenit.eu
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.euwww.xenit.eu
www.xenit.eu
Alfred GDPR Desktop and Finder
• Alfred Desktop and Alfred Finder control what you can:
• Search
• Modify
• See (list, export …)
• Extended Control to:
• Search Forms
• Meta-Data Forms
• Results Columns
• Filter Values
Define GDPR access roles based upon information
classification
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.euwww.xenit.eu
www.xenit.eu
Alfred GDPR Server package
• Document Model extensions for GDPR classification
• GDPR access control filters
• Custom behaviour to:
• Execute governance actions on Cat 1, Cat2, Cat3
documents
• Request to forget
• Record consent to use
• Extend corporate customers policies:
• Additional classification, extended ACL, RACI control
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.euwww.xenit.eu
www.xenit.eu
Alfred GDPR Detect
• 2017 Release
• Detect PII patterns (account number, id number) and
personal information based upon regular expression
and post-qualification
• Can handle documents and emails
• Uses search services to identify documents with
personal data
• 2018 Release: Applying Machine Learning to classify
information in three GDPR classes
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.euAlfred GDPR Approach
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
CDI-Partners
GDPR Principles
www.xenit.eu
Bart Van Bouwel – Managing Partner
Xenit
GDPR Challenges
Ronny Timmermans – CEO and Managing Director
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
GDPR Challenges
Data classification
Identify documents containing
personal data and label them
appropriately
Document and metadata
Security
State of the art security of the
documents and the metadata
Access control
Monitor and control access to
the documents, store metadata
to proof legitimate purpose
Safe offline storage
Make documents available
offline in a secure way
Third parties
Control the usage of
documents by
external parties
Breaches
Detect breaches
Documents deletion
Keep track of the right time to
delete documents and
permanently delete the
documents. No backup copies
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Identify documents containing personal data and
label them appropriately
• Alfred Detect for identification
• Regular expression
• NLP for detection of “names”
• Alfred Desktop and Alfred Finder to add the
information as meta-data
• Alfred GDPR AMP for data qualification aspects
• Audit labelling and unlabelling GDPR aspects
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
State of the art security of the documents and
the metadata
• Alfred Edge – Access control on properties
according to GDPR roles
• Display and modify properties according to GDPR
roles
• Encryption of GDPR information
• Encryption of database
• Protection of your indexes
BEST PRACTI
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Monitor and control access to the documents,
store metadata to proof legitimate purpose
• Send out controlled URL (HMAC)
• Who has accessed
• Validity period
• API auditing
• Block before any damage
• Full Alfresco auditing
• Alfred provides extended auditing in which
changing of ACL’s can be monitored
BEST PRACTI
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Make documents available off-line in a secure
way
• Alfred Desktop GDPR
• Local encryption of documents
• Clean up after “editing”
• Fully transparent to the users
• Alfred Desktop and Alfred Finder GDPR
• Control the role to download GDPR
information
• Watermark off-line content (PDF)
BEST PRACTI
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Detect breaches
• Alfred Edge (API Gateway)
• All accesses (internal and external) are logged
• Set alarms on export or search operations on
large privacy sensitive data
• Check “denied access” failure internally and
externally and take appropriate action
• Alfresco auditing
BEST PRACTI
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Delete or shield privacy related
documents “as soon as appropriate”
• Set a good retention policy
• As soon as appropriate set more stringent ACL rules
on documents
• On the desktop, remove after consultation or
editing (automated by Alfred Desktop)
• Alfresco Governance Services for complex cases
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Use documents control by external parties
• Share by link
• Share content = explicit action for GDPR related
documents
• Register who sent the link
• Register who got the link
• Audit use via link
• Control life time of the link
• Optionally: Identify who accesses the resource
via link (via OAuth2 and
LinkedIn/Twitter/Gmail)
BEST PRACTI
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
CDI-Partners
GDPR Principles
www.xenit.eu
Bart Van Bouwel – Managing Partner
Xenit
Top tips to start preparing for the GDPR
Ronny Timmermans – CEO and Managing Director
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Top tips to start preparing for the
GDPR
Share a controlled copy
Encrypt the sensitive information
Show on a need to know basis
Share
Encrypt
Show
Audit & Report
• When sharing a copy of a Cat1-3 document, the system requires you to share the
copy and to indicate with who you are sharing
• Mark copies that are shared with
• Watermark (you “x” have received from “y’)
• Self-identifying document
Dispose
• Metadata
• Encryption at rest of documents
• You can only search what you need to know (encryption)
• You can only retrieve (decryption) what you require
Audit everything and report appropriately
Dispose as soon as possible (not sooner)
BEST PRACTI
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
CDI-Partners
GDPR Principles
www.xenit.eu
Bart Van Bouwel – Managing Partner
Xenit
Xenit Use Case: Screening 3M documents and 8M emails for sensitive data
Thijs Lemmens - ECM Architect
Giovanni Boscarino - ECM Senior Software Engineer
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu 28
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu 29
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu 30
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu 31
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu 32
Q&A
www.xenit.eu
| © 2017 XeniT Solutions. All rights reserved.
www.xenit.eu
Get in touch
Experienced Alfresco partner to help drive your Digital Transformation.
General Protection Data Regulation
A solution to manage your unstructured data
BUSINESS FEATURES 2017
© 2017 XeniT Solutions. All rights reserved.
Thank you

More Related Content

What's hot

Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...Ardoq
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideZymplify
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceIDERA Software
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017Amarach Research
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparationPromapp Solutions
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Csa privacy by design & gdpr austin chambers 11-4-17
Csa   privacy by design & gdpr austin chambers 11-4-17Csa   privacy by design & gdpr austin chambers 11-4-17
Csa privacy by design & gdpr austin chambers 11-4-17Trish McGinity, CCSK
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers Gary Dodson
 
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Codemotion
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationIBM Security
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...DATUM LLC
 

What's hot (20)

Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Csa privacy by design & gdpr austin chambers 11-4-17
Csa   privacy by design & gdpr austin chambers 11-4-17Csa   privacy by design & gdpr austin chambers 11-4-17
Csa privacy by design & gdpr austin chambers 11-4-17
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
 
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity Legislation
 
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
 

Similar to How to implement gdpr in your document repository

CBC GDPR The Physics
CBC GDPR The PhysicsCBC GDPR The Physics
CBC GDPR The PhysicsJason Chapman
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRMatt Stubbs
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR ComplianceGabor Farkas
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessSirius
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
General Data Protection Regulation - BDW Meetup, October 11th, 2017
General Data Protection Regulation - BDW Meetup, October 11th, 2017General Data Protection Regulation - BDW Meetup, October 11th, 2017
General Data Protection Regulation - BDW Meetup, October 11th, 2017Caserta
 
IAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe
 
[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your Information
[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your Information[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your Information
[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your InformationAIIM International
 
Data compliance - get it right the first time (Full color PDF)
Data compliance - get it right the first time (Full color PDF)Data compliance - get it right the first time (Full color PDF)
Data compliance - get it right the first time (Full color PDF)Peter GEELEN ✔
 
Data compliance - get it right the first time (Black/White printable PDF)
Data compliance - get it right the first time (Black/White printable PDF)Data compliance - get it right the first time (Black/White printable PDF)
Data compliance - get it right the first time (Black/White printable PDF)Peter GEELEN ✔
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessOlivier BARROT
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical OverviewErnest Staats
 
The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help Niklas Hjorthen
 
Le soluzioni tecnologiche a supporto della normativa GDPR
Le soluzioni tecnologiche a supporto della normativa GDPRLe soluzioni tecnologiche a supporto della normativa GDPR
Le soluzioni tecnologiche a supporto della normativa GDPRJürgen Ambrosi
 
Data Protection Forum meetup 23052017
Data Protection Forum meetup   23052017 Data Protection Forum meetup   23052017
Data Protection Forum meetup 23052017 John M Walsh
 

Similar to How to implement gdpr in your document repository (20)

CBC GDPR The Physics
CBC GDPR The PhysicsCBC GDPR The Physics
CBC GDPR The Physics
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPR
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdprSharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
Sharp Cookie Advisors legal_botar_ai_dataskydd_gdpr
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
General Data Protection Regulation - BDW Meetup, October 11th, 2017
General Data Protection Regulation - BDW Meetup, October 11th, 2017General Data Protection Regulation - BDW Meetup, October 11th, 2017
General Data Protection Regulation - BDW Meetup, October 11th, 2017
 
IAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance PrimerIAB Europe's GDPR Compliance Primer
IAB Europe's GDPR Compliance Primer
 
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection CommissionersGDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
 
[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your Information
[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your Information[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your Information
[Webinar Slides] Data Privacy – Learn What It Takes to Protect Your Information
 
GDPR How to get started?
GDPR  How to get started?GDPR  How to get started?
GDPR How to get started?
 
Data compliance - get it right the first time (Full color PDF)
Data compliance - get it right the first time (Full color PDF)Data compliance - get it right the first time (Full color PDF)
Data compliance - get it right the first time (Full color PDF)
 
Data compliance - get it right the first time (Black/White printable PDF)
Data compliance - get it right the first time (Black/White printable PDF)Data compliance - get it right the first time (Black/White printable PDF)
Data compliance - get it right the first time (Black/White printable PDF)
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 
GDPR Benefits and a Technical Overview
GDPR  Benefits and a Technical OverviewGDPR  Benefits and a Technical Overview
GDPR Benefits and a Technical Overview
 
The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help The EU General Protection Regulation and how Oracle can help
The EU General Protection Regulation and how Oracle can help
 
Le soluzioni tecnologiche a supporto della normativa GDPR
Le soluzioni tecnologiche a supporto della normativa GDPRLe soluzioni tecnologiche a supporto della normativa GDPR
Le soluzioni tecnologiche a supporto della normativa GDPR
 
Data Protection Forum meetup 23052017
Data Protection Forum meetup   23052017 Data Protection Forum meetup   23052017
Data Protection Forum meetup 23052017
 

More from XeniT Solutions nv

Data Security in the Insurance Industry: what you need to know about data pro...
Data Security in the Insurance Industry: what you need to know about data pro...Data Security in the Insurance Industry: what you need to know about data pro...
Data Security in the Insurance Industry: what you need to know about data pro...XeniT Solutions nv
 
Driving full-scale productivity and collaboration with the Alfresco connector...
Driving full-scale productivity and collaboration with the Alfresco connector...Driving full-scale productivity and collaboration with the Alfresco connector...
Driving full-scale productivity and collaboration with the Alfresco connector...XeniT Solutions nv
 
How to solve your toughest performance issues in Alfresco
How to solve your toughest performance issues in AlfrescoHow to solve your toughest performance issues in Alfresco
How to solve your toughest performance issues in AlfrescoXeniT Solutions nv
 
How do you secure an electronic signature?
How do you secure an electronic signature?How do you secure an electronic signature?
How do you secure an electronic signature?XeniT Solutions nv
 
How to increase user's productivity with Alfred Desktop and Alfred Finder
How to increase user's productivity with Alfred Desktop and Alfred FinderHow to increase user's productivity with Alfred Desktop and Alfred Finder
How to increase user's productivity with Alfred Desktop and Alfred FinderXeniT Solutions nv
 
How to Scale Information Dissemination to the Virtual Digital Workspace
How to Scale Information Dissemination to the Virtual Digital WorkspaceHow to Scale Information Dissemination to the Virtual Digital Workspace
How to Scale Information Dissemination to the Virtual Digital WorkspaceXeniT Solutions nv
 
THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...
THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...
THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...XeniT Solutions nv
 
Webinar | New release Alfred Desktop 3.7
Webinar | New release Alfred Desktop 3.7Webinar | New release Alfred Desktop 3.7
Webinar | New release Alfred Desktop 3.7XeniT Solutions nv
 
Webinar: How to turn Alfresco Digital Business Platform into a Managed Service
Webinar: How to turn Alfresco Digital Business Platform into a Managed ServiceWebinar: How to turn Alfresco Digital Business Platform into a Managed Service
Webinar: How to turn Alfresco Digital Business Platform into a Managed ServiceXeniT Solutions nv
 
Key points quality leaders should know about intelligent information manageme...
Key points quality leaders should know about intelligent information manageme...Key points quality leaders should know about intelligent information manageme...
Key points quality leaders should know about intelligent information manageme...XeniT Solutions nv
 
Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...
Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...
Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...XeniT Solutions nv
 
Leuven European actuarial journal conference 20180911
Leuven European actuarial journal conference 20180911Leuven European actuarial journal conference 20180911
Leuven European actuarial journal conference 20180911XeniT Solutions nv
 
How to configure alfred desktop in your alfresco project in two days
How to configure alfred desktop in your alfresco project in two daysHow to configure alfred desktop in your alfresco project in two days
How to configure alfred desktop in your alfresco project in two daysXeniT Solutions nv
 
GDPR READY SOLUTION FOR UNSTRUCTURED DATA
GDPR READY SOLUTION FOR UNSTRUCTURED DATAGDPR READY SOLUTION FOR UNSTRUCTURED DATA
GDPR READY SOLUTION FOR UNSTRUCTURED DATAXeniT Solutions nv
 
REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...
REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...
REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...XeniT Solutions nv
 
Introducing Alfred Desktop 3.6
Introducing Alfred Desktop 3.6 Introducing Alfred Desktop 3.6
Introducing Alfred Desktop 3.6 XeniT Solutions nv
 
Introducing Alfred Finder 2.0
Introducing Alfred Finder 2.0 Introducing Alfred Finder 2.0
Introducing Alfred Finder 2.0 XeniT Solutions nv
 
20151201 swm elba_alfresco_user_day_wien
20151201 swm elba_alfresco_user_day_wien20151201 swm elba_alfresco_user_day_wien
20151201 swm elba_alfresco_user_day_wienXeniT Solutions nv
 
Usg people netherlands Alfresco User Day Amsterdam 3 dec 2015
Usg people netherlands   Alfresco User Day Amsterdam 3 dec 2015Usg people netherlands   Alfresco User Day Amsterdam 3 dec 2015
Usg people netherlands Alfresco User Day Amsterdam 3 dec 2015XeniT Solutions nv
 

More from XeniT Solutions nv (20)

Data Security in the Insurance Industry: what you need to know about data pro...
Data Security in the Insurance Industry: what you need to know about data pro...Data Security in the Insurance Industry: what you need to know about data pro...
Data Security in the Insurance Industry: what you need to know about data pro...
 
Driving full-scale productivity and collaboration with the Alfresco connector...
Driving full-scale productivity and collaboration with the Alfresco connector...Driving full-scale productivity and collaboration with the Alfresco connector...
Driving full-scale productivity and collaboration with the Alfresco connector...
 
How to solve your toughest performance issues in Alfresco
How to solve your toughest performance issues in AlfrescoHow to solve your toughest performance issues in Alfresco
How to solve your toughest performance issues in Alfresco
 
How do you secure an electronic signature?
How do you secure an electronic signature?How do you secure an electronic signature?
How do you secure an electronic signature?
 
How to increase user's productivity with Alfred Desktop and Alfred Finder
How to increase user's productivity with Alfred Desktop and Alfred FinderHow to increase user's productivity with Alfred Desktop and Alfred Finder
How to increase user's productivity with Alfred Desktop and Alfred Finder
 
How to Scale Information Dissemination to the Virtual Digital Workspace
How to Scale Information Dissemination to the Virtual Digital WorkspaceHow to Scale Information Dissemination to the Virtual Digital Workspace
How to Scale Information Dissemination to the Virtual Digital Workspace
 
THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...
THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...
THE ALFRESCO FOUNDATION ARCHITECTURE FOR INTEGRATED FULL DIGITAL INSURANCE PR...
 
Webinar | New release Alfred Desktop 3.7
Webinar | New release Alfred Desktop 3.7Webinar | New release Alfred Desktop 3.7
Webinar | New release Alfred Desktop 3.7
 
Webinar: How to turn Alfresco Digital Business Platform into a Managed Service
Webinar: How to turn Alfresco Digital Business Platform into a Managed ServiceWebinar: How to turn Alfresco Digital Business Platform into a Managed Service
Webinar: How to turn Alfresco Digital Business Platform into a Managed Service
 
Key points quality leaders should know about intelligent information manageme...
Key points quality leaders should know about intelligent information manageme...Key points quality leaders should know about intelligent information manageme...
Key points quality leaders should know about intelligent information manageme...
 
Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...
Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...
Decouple and simplify access to Alfresco with Alfred Edge - Webinar September...
 
Leuven European actuarial journal conference 20180911
Leuven European actuarial journal conference 20180911Leuven European actuarial journal conference 20180911
Leuven European actuarial journal conference 20180911
 
How to configure alfred desktop in your alfresco project in two days
How to configure alfred desktop in your alfresco project in two daysHow to configure alfred desktop in your alfresco project in two days
How to configure alfred desktop in your alfresco project in two days
 
Xenit diary dev con 2018
Xenit diary dev con 2018Xenit diary dev con 2018
Xenit diary dev con 2018
 
GDPR READY SOLUTION FOR UNSTRUCTURED DATA
GDPR READY SOLUTION FOR UNSTRUCTURED DATAGDPR READY SOLUTION FOR UNSTRUCTURED DATA
GDPR READY SOLUTION FOR UNSTRUCTURED DATA
 
REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...
REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...
REDUCING TOTAL COST OF OWNERSHIP AND INCREASING SCALABILITY WITH XENIT SOLUTI...
 
Introducing Alfred Desktop 3.6
Introducing Alfred Desktop 3.6 Introducing Alfred Desktop 3.6
Introducing Alfred Desktop 3.6
 
Introducing Alfred Finder 2.0
Introducing Alfred Finder 2.0 Introducing Alfred Finder 2.0
Introducing Alfred Finder 2.0
 
20151201 swm elba_alfresco_user_day_wien
20151201 swm elba_alfresco_user_day_wien20151201 swm elba_alfresco_user_day_wien
20151201 swm elba_alfresco_user_day_wien
 
Usg people netherlands Alfresco User Day Amsterdam 3 dec 2015
Usg people netherlands   Alfresco User Day Amsterdam 3 dec 2015Usg people netherlands   Alfresco User Day Amsterdam 3 dec 2015
Usg people netherlands Alfresco User Day Amsterdam 3 dec 2015
 

Recently uploaded

M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechNewman George Leech
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Tina Ji
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...noida100girls
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdfOrient Homes
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Roomdivyansh0kumar0
 

Recently uploaded (20)

M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman Leech
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdf
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
 

How to implement gdpr in your document repository

  • 1. How to implement GDPR in the document repository Xenit - December, 11 2017 December, 5 2017 4 pm - 5 pm CET
  • 2. Agenda • CDI-Partners Testimonial: GDPR Principles [15 min] • Alfresco Testimonial: How Alfresco can help your organization comply with the GDPR [15 min] • Xenit Testimonial: A managed shared drive [15 min] • Top tips to start preparing for the GDPR [5 min] • Xenit Use Case [5 min] • Q&A session [5 min] How to implement GDPR in the document repository
  • 3. CDI-Partners GDPR Principles www.xenit.eu Bart Van Bouwel – Managing Partner CDI-Partners GDPR Principles Bart Van Bouwel – Managing Partner
  • 4. CDI-Partners Testimonial Bart Van Bouwel – Managing Partner - CDI-Partners “Did you know that most data breaches reported are related to unstructured data? Documents, spreadsheets, mails and even paper files? Without a clear focus on documents, companies can’t claim adequate protection of personal data.”
  • 5. How to implement GDPR in the document repository Bart Van Bouwel bart.van.bouwel@cdi-partners.be
  • 6. General Data Protecting Regulation Purpose Give individuals control over their personal data Applies to All companies that process personal data of EU citizens European Regulation One law across the EU, enforced as of May 25th, 2018
  • 7. Some Principles Lawfully, fairly and transparent Collected for specified, explicit and legitimate purposes Adequate, relevant and limited  Data Minimization Processing must be Consult, correct, request deletion, portability of their personal data Rights of Data Subjects Privacy by design – Privacy by default Data Breach notification is mandatory
  • 8. Fines Up to € 20.000.000 or 4 % of total worldwide annual turnover Proportional to the scale of the infringements Other measures possible Issue warnings and reprimands Order to comply with the data subject's requests Order to bring processing operations into compliance Order to communicate a personal data breach to the data subject Impose a temporary or definitive limitation including a ban on processing …
  • 9. Personal Data Home & work information Health information Finger print & Genetic information Family & demographic information Online behaviour & shopping information Union membership Political opinions Religion & Race Information relating to an identified or identifiable natural person Personal data can be structured (databases) or unstructured (documents, listings, reports, spreadsheets, …)
  • 10. Stored in databases Accessed through applications More control  More easy to protect Structured data In documents and files Stored on local or network drives / Cloud / USB Keys / … Easily copied and distributed Less control  More difficult to protect Unstructured data Structured data or Unstructured data? Where to start? Where to focus
  • 11. GDPR in practice No GDPR examples available Based upon EU Data Protection Directive 1995 Data breach notification is a best practice Maximum fine £ 500.000 Data Protection Act 1998 (UK) Information available about breaches and sanctions ICO – Information Commissioners’ Office
  • 12. Examples of Data Breaches Data Protection Act - Source: ICO (January – March 2017) – 678 breaches Loss/theft of paperwork 13% Unauthorised or unlawful processing 21% Data posted/faxed incorrect recipient 11%Data emailed to incorrect recipient 11% Cyber incident 14% Failure to redact data 7% Failure to use bcc 5% Data left in insecure location 4% Other 9% Loss/theft of unencrypted device 4% Verbal Disclosure 1% Document related >50% related to documents
  • 13. Fines by ICO Marketing 42% Process 30% Theft (employee) 19% IT - Security 9% Categories of Fines Data Protection Act - Source: ICO (January – September 2017) • 42% Marketing  Mostly deliberate actions with positive ROI • Biggest risk are found in the 58% • Some examples – Sensitive data lost in the mail – Employees accessing or stealing sensitive data – A cyber attack stealing 30.000 emails – Leaving paper files in a cabinet that was sold – A laptop containing sensitive documents that was stolen – Backing up sensitive documents to a free cloud storage • All these fines where given for breaches relating to unstructured data • Most breaches and almost all cases that are fined are from undeliberate or deliberate acts from within the company
  • 14. Conclusion • Fines will be given after someone files a complaint – Focus on solutions to prevent data breaches • Start with – Processes related to rights of individuals • Privacy statements / proof of consent / demands to access – correct – erase data – Unstructured data • What functionalities do you need for your documents?
  • 15. Challenges for unstructured data 1. Identify documents containing personal data and label them appropriately 2. State of the art security of the documents and the metadata 3. Monitor and control access to the documents, store metadata to prove legitimate purpose 4. Make documents available offline in a secure way 5. Detect breaches 6. Keep track of the right time to delete documents and permanently delete the documents so no backup copies exist 7. Control the usage of documents by external parties
  • 16. CDI-Partners GDPR Principles www.xenit.eu Bart Van Bouwel – Managing Partner Alfresco How the Alfresco Digital Business Platform can help your company comply with GDPR George Parapadakis – Director, Business Solutions Strategy - EMEA
  • 17. Alfresco Testimonial George Parapadakis – Business Solutions Strategy - Alfresco “GDPR will touch every department, every function and every operation inside your organization. It will not only change the way you manage information, it will change the way people behave.”
  • 18. The Alfresco Digital Business Platform for George Parapadakis November 2017
  • 19. Over 24 GDPR Articles we can help with… • Lawful Processing, Minimisation, Consent, PII detection • Right of Access • Right to Correct data (Rectification) • Right to be Forgotten (Erasure) • Right to Data Portability • Right to Object / Withdraw consent • Data Protection and Security (Pseudonymisation) • Keeping Records of Processing • Report Data Breaches • Data Protection Impact Assessments • 3rd Party Notification • Automated Decision Making • Policy Management • Certification • Data Residency Article 15 Article 16 Article 20 Article 25, 32 Article 7, 18, 21 Article 30 Article 17 Article 5, 6, 7, 9 Article 19 Article 40 Article 45, 46 Article 42 Article 33, 34 Article 35, 36 Article 22
  • 20. Alfresco Digital Business Platform Application Development Framework Alfresco Process Services Alfresco Content Services Integrations / Extensions Open APIs and Open Standards On-Prem, Cloud, Hybrid, Managed Intelligence and Analytics Alfresco Governance Services
  • 21. Alfresco Digital Business Platform Application Development Framework Alfresco Process Services Alfresco Content Services Integrations / Extensions Open APIs and Open Standards On-Prem, Cloud, Hybrid, Managed Intelligence and Analytics Alfresco Governance Services
  • 22. Alfresco GDPR Framework Managing Policies & Certify Users policy authoring, review, approval, distribution and sign-off (ACS) Identify, protect and manage GDPR sensitive content metadata and aspects to create a GDPR Asset Register (ACS) Classification Marks to secure access to PII (AGS) Execute disposition policies (AGS) Manage GDPR related processes Define and execute Subject Access Requests, data portability, erasure, etc. (APS) Manage Breach Notifications and Impact assessments (APS) Compliance & Audit Reporting
  • 23. Policy Management 6 Capture Audit Trail Policy Template Collaborative Authoring Author Author Author Author Revise Approve & Certificate
  • 24. Alfresco GDPR Framework Managing Policies & Certify Users policy authoring, review, approval, distribution and sign-off (ACS) Identify, protect and manage GDPR sensitive content metadata and aspects to create a GDPR Asset Register (ACS) Classification Marks to secure access to PII (AGS) Execute disposition policies (AGS) Manage GDPR related processes Define and execute Subject Access Requests, data portability, erasure, etc. (APS) Manage Breach Notifications and Impact assessments (APS) Compliance & Audit Reporting
  • 25. GDPR Asset Register Security Marks Finance Legal Marketing HR Group A Audit Trail ….. Redacted / Pseudonymised
  • 26. Alfresco GDPR Framework Managing Policies & Certify Users policy authoring, review, approval, distribution and sign-off (ACS) Identify, protect and manage GDPR sensitive content metadata and aspects to create a GDPR Asset Register (ACS) Classification Marks to secure access to PII (AGS) Execute disposition policies (AGS) Manage GDPR related processes Define and execute Subject Access Requests, data portability, erasure, etc. (APS) Manage Breach Notifications and Impact assessments (APS) Compliance & Audit Reporting
  • 27. Subject Access Request Capture Audit Trail Amend Systems Collect Data Notify 3rd parties Withdraw Consent Assemble Output Prepare Response Review Response Respond to Customer Capture Audit Trail TriageValidate Request Amendments Consent Withdrawal Data Portability Erasure Email Phone Letter In Person Internal ACS File System LoB Integration External Process External ECM Cloud EFSS Manual
  • 28. Alfresco GDPR Framework Managing Policies & Certify Users policy authoring, review, approval, distribution and sign-off (ACS) Identify, protect and manage GDPR sensitive content metadata and aspects to create a GDPR Asset Register (ACS) Classification Marks to secure access to PII (AGS) Execute disposition policies (AGS) Manage GDPR related processes Define and execute Subject Access Requests, data portability, erasure, etc. (APS) Manage Breach Notifications and Impact assessments (APS) Compliance & Audit Reporting
  • 29. Typical GDPR Reports Asset Register SAR Dashboard Record of Processing Certification Impact Assessments Policy Impact List, by law
  • 30. Digital Business Platform = “Data Privacy By Design” ü Secure place for GDPR information & metadata ü Maximise automation to enforce compliance controls ü Proactively collect audit trails & evidence
  • 32. CDI-Partners GDPR Principles www.xenit.eu Bart Van Bouwel – Managing Partner Xenit Alfred GDPR Approach Ronny Timmermans – CEO and Managing Director
  • 33. Xenit Testimonial Ronny Timmermans – CEO, Managing Director - Xenit “Governance has always been a concern of Xenit and a particular strength of Alfresco. GDPR makes us more aware that data are valuable assets, with privacy and sensitivity implications for every individual we interact with in our corporate environment. Building upon the enterprise capabilities of Alfresco and leveraging our Alfred products, data protection comes by design and not as an afterthought. ”
  • 34. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu 9 GDPR DATA CLASSIFICATION PERSONAL DATA [Cat 1] a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, economic, cultural or social identity SENSITIVE INFORMATION [Cat 2] on racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data SENSITIVE DATA [Cat 3] Relating to criminal convictions and offences DATA PROCESSING MANDATE • A private company can claim legitimate interest to process Cat 1 • Consent to process Sensitive information • Cat 3 can be processed under the control of an Official Authority
  • 35. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Alfred Protection Principles Protection Principle 1 Unless you know the key (name, other id) you cannot retrieve information about a person. Protection Principle 2 Only when you have the appropriate role, you can view and consult Cat1, Cat2 and Cat3 data in the user interface.
  • 36. | © 2017 XeniT Solutions. All rights reserved. www.xenit.euwww.xenit.eu Alfred GDPR package • Build upon Alfresco ACS, can be enriched with: • Alfresco Process Services • Alfresco Governance Services • Alfred GDPR contains: • GDPR edition of Alfred Desktop and Alfred Finder • Alfred Edge with audit, query control and GDPR access rules • Alfred GDPR Model and Behaviour • Option Module: Alfred GDPR Detect PII www.xenit.eu
  • 37. | © 2017 XeniT Solutions. All rights reserved. www.xenit.euwww.xenit.eu www.xenit.eu Alfred GDPR Desktop and Finder • Alfred Desktop and Alfred Finder control what you can: • Search • Modify • See (list, export …) • Extended Control to: • Search Forms • Meta-Data Forms • Results Columns • Filter Values Define GDPR access roles based upon information classification
  • 38. | © 2017 XeniT Solutions. All rights reserved. www.xenit.euwww.xenit.eu www.xenit.eu Alfred GDPR Server package • Document Model extensions for GDPR classification • GDPR access control filters • Custom behaviour to: • Execute governance actions on Cat 1, Cat2, Cat3 documents • Request to forget • Record consent to use • Extend corporate customers policies: • Additional classification, extended ACL, RACI control
  • 39. | © 2017 XeniT Solutions. All rights reserved. www.xenit.euwww.xenit.eu www.xenit.eu Alfred GDPR Detect • 2017 Release • Detect PII patterns (account number, id number) and personal information based upon regular expression and post-qualification • Can handle documents and emails • Uses search services to identify documents with personal data • 2018 Release: Applying Machine Learning to classify information in three GDPR classes
  • 40. | © 2017 XeniT Solutions. All rights reserved. www.xenit.euAlfred GDPR Approach
  • 41. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu CDI-Partners GDPR Principles www.xenit.eu Bart Van Bouwel – Managing Partner Xenit GDPR Challenges Ronny Timmermans – CEO and Managing Director
  • 42. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu GDPR Challenges Data classification Identify documents containing personal data and label them appropriately Document and metadata Security State of the art security of the documents and the metadata Access control Monitor and control access to the documents, store metadata to proof legitimate purpose Safe offline storage Make documents available offline in a secure way Third parties Control the usage of documents by external parties Breaches Detect breaches Documents deletion Keep track of the right time to delete documents and permanently delete the documents. No backup copies
  • 43. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Identify documents containing personal data and label them appropriately • Alfred Detect for identification • Regular expression • NLP for detection of “names” • Alfred Desktop and Alfred Finder to add the information as meta-data • Alfred GDPR AMP for data qualification aspects • Audit labelling and unlabelling GDPR aspects
  • 44. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu State of the art security of the documents and the metadata • Alfred Edge – Access control on properties according to GDPR roles • Display and modify properties according to GDPR roles • Encryption of GDPR information • Encryption of database • Protection of your indexes BEST PRACTI
  • 45. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Monitor and control access to the documents, store metadata to proof legitimate purpose • Send out controlled URL (HMAC) • Who has accessed • Validity period • API auditing • Block before any damage • Full Alfresco auditing • Alfred provides extended auditing in which changing of ACL’s can be monitored BEST PRACTI
  • 46. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Make documents available off-line in a secure way • Alfred Desktop GDPR • Local encryption of documents • Clean up after “editing” • Fully transparent to the users • Alfred Desktop and Alfred Finder GDPR • Control the role to download GDPR information • Watermark off-line content (PDF) BEST PRACTI
  • 47. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Detect breaches • Alfred Edge (API Gateway) • All accesses (internal and external) are logged • Set alarms on export or search operations on large privacy sensitive data • Check “denied access” failure internally and externally and take appropriate action • Alfresco auditing BEST PRACTI
  • 48. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Delete or shield privacy related documents “as soon as appropriate” • Set a good retention policy • As soon as appropriate set more stringent ACL rules on documents • On the desktop, remove after consultation or editing (automated by Alfred Desktop) • Alfresco Governance Services for complex cases
  • 49. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Use documents control by external parties • Share by link • Share content = explicit action for GDPR related documents • Register who sent the link • Register who got the link • Audit use via link • Control life time of the link • Optionally: Identify who accesses the resource via link (via OAuth2 and LinkedIn/Twitter/Gmail) BEST PRACTI
  • 50. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu CDI-Partners GDPR Principles www.xenit.eu Bart Van Bouwel – Managing Partner Xenit Top tips to start preparing for the GDPR Ronny Timmermans – CEO and Managing Director
  • 51. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Top tips to start preparing for the GDPR Share a controlled copy Encrypt the sensitive information Show on a need to know basis Share Encrypt Show Audit & Report • When sharing a copy of a Cat1-3 document, the system requires you to share the copy and to indicate with who you are sharing • Mark copies that are shared with • Watermark (you “x” have received from “y’) • Self-identifying document Dispose • Metadata • Encryption at rest of documents • You can only search what you need to know (encryption) • You can only retrieve (decryption) what you require Audit everything and report appropriately Dispose as soon as possible (not sooner) BEST PRACTI
  • 52. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu CDI-Partners GDPR Principles www.xenit.eu Bart Van Bouwel – Managing Partner Xenit Xenit Use Case: Screening 3M documents and 8M emails for sensitive data Thijs Lemmens - ECM Architect Giovanni Boscarino - ECM Senior Software Engineer
  • 53. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu 28
  • 54. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu 29
  • 55. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu 30
  • 56. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu 31
  • 57. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu 32 Q&A www.xenit.eu
  • 58. | © 2017 XeniT Solutions. All rights reserved. www.xenit.eu Get in touch Experienced Alfresco partner to help drive your Digital Transformation. General Protection Data Regulation A solution to manage your unstructured data BUSINESS FEATURES 2017
  • 59. © 2017 XeniT Solutions. All rights reserved. Thank you