SlideShare a Scribd company logo
In partnership with SCOS
1
IPSWITCH
Paolo Ferrari
Director, Solution Sales and Professional Services -
EMEA, APAC and LATAM at Ipswitch, Inc.
Sébastien Roques
Regional Sales Manager Northern Europe at Ipswitch,
Inc.
2
3
Jonathan Armstrong
Jonathan is an experienced lawyer with a
concentration on technology and compliance.
His practice includes advising multinational
companies on matters involving risk,
compliance and technology across Europe.
He has handled legal matters in more than 60
countries involving emerging technology,
corporate governance, ethics code
implementation, reputation, internal
investigations, marketing, branding and global
privacy policies
Why are we
here today ?
5
World’s biggest data breaches In 2015. Showing losses over 30.000 records and up.
SURVEY
8
2016 State of Data Security and Compliance
About us….
10
Ipswitch Company Overview
Company Overview
• Founded 1991
• Headquarters: Lexington,
MA
• Remote Offices:
• Alpharetta, GA
• Madison, WI
• Heidelberg, Germany
• 300 Employees
Financials
• Privately Held
• Revenues of $76M+ in
2015
• Over 55% Recurring
Revenue
• Over 50% of Revenues
from Indirect Channel
• 30% from International
• Double Digit EBITDA
Margin
• No Debt
Customer Overview
• 25,000+ Active customers
• Across 168 countries
• Present in a wide array of
industry verticals
• Strong renewal rates on
both product lines
11
One Ipswitch: 2 minute company overview
12
LARGE AND THRIVING
CUSTOMER BASE
Over 25,000 Global SMB,
Government & Enterprise Customers
SECURE CONTROL
of Business Transactions,
Applications and Infrastructure
CORE PRODUCT LINES
IT and Network Monitoring
Secure Information and File
Transfer
The Pioneer in
EASY TO TRY,
BUY AND USE
IT Management Software
2
Option 2
Ipswitch at a Glance
13
MOVEit
Managed File Transfer
WS_FTP
Secure File Transfer
MessageWay
B2B File Transfer and Integration
Ipswitch Analytics
SLA and Compliance Analytics
WhatsUp Gold
Unified Network, Server & App
Monitoring
Event & Log Management
Collects, store and analyze log files
AlertFox
Web Performance Monitoring
Secure Information
and File Transfer
Ipswitch Products
IT Monitoring
and Management
25,000+ active customers in 116 countries
All you need to know about GDPR but
are too afraid to ask...
12 October 2016
Jonathan Armstrong
@CorderyUK 16
© Cordery 2016
Data Security - Landscape
• Personal data has a value
• Different political reactions
• Different legal systems worldwide
• Different enforcement even within Europe
• Contrasting approach Europe -v- US
• Snowden has changed the game
• Schrems has had a real impact
• GDPR already a reality
© Cordery 2016 17
Current UK Legislative background
“Appropriate technical and organisational measures
shall be taken against unauthorised or unlawful
processing of personal data and against accidental loss
or destruction of, or damage to, personal data.”
@CorderyUK 18
© Cordery 2016
Section 13 of the Dutch Personal Data Protection Act
“The controller implements appropriate
technical and organisational measures to
protect personal data against loss or any
unlawful forms of processing. Having regard to
the state of the art and the cost of their
implementation, such measures will guarantee a
level of security appropriate to the risks
represented by the processing and the nature of
the data to be protected. These measures also
seek to prevent the unnecessary collection and
further processing of personal data.”
* unofficial translation
@CorderyUK 19
© Cordery 2016
Example: South Wales Police
• South Wales Police had sensitive films from victims
• They recorded the interviews
• They moved the videos between offices, courts etc. on
DVD
• The DVDs were encrypted & stored in a desk drawer
• The DVDs were lost after an office move although the
loss was not reported for two years
• Victim made a formal complaint
• Prosecution prejudiced
• ICO fined South Wales Police £160,000
@CorderyUK 20
© Cordery 2016
Prevention
Dutch AP:
“Contingency plan
Every organisation should have a contingency
plan indicating exactly what is to happen in the
event of an emergency. However, such a plan is
useful only if personnel are familiar with it and
regular drills have been held to practise its
implementation...”
@CorderyUK 21
© Cordery 2016
New EU data rules
• A = aims
• B = benefits
• C = consequences
@CorderyUK 22
© Cordery 2016
New EU data rules - Aims
• Proposed Regulation not Directive (but with carve-outs)
• Data protection by design/default
• Data Protection Impact Assessments (aka PIAs)
• Suppliers outside EU in scope
• Toughened (local not centralised) enforcement bodies -
audits & dawn raids
• Breach reporting in 72 hours
• Distinction between processor and controller
diminishes
• Data Protection Officers
• Transfers to 3rd countries - Binding Corporate Rules
@CorderyUK 23
© Cordery 2016
New EU data rules - Benefits
• No general registration requirement?
• One stop shop?
• Consent less of an option?
• Right to be forgotten?
• Right to portability?
• Right to object to profiling?
• Enhanced SAR Regime?
@CorderyUK 24
© Cordery 2016
New EU data rules - Consequences
• More to do for controllers and processors
• Liability & compensation (material or non-material
damage)
• Fines of up to 4% of global annual turnover
• Shared investigations across the EU
• Greater reputational risk
• Shareholder/investor engagement
@CorderyUK 25
© Cordery 2016
GDPR already a reality
• Data breach reporting laws in Germany, Austria and The
Netherlands (but not identical to GDPR)
• Usually a notification in The Netherlands to the AP must be
done “immediately” and in any case within 72 hours – AP
received 1,500+ notifications in first four months, c.70
regulatory actions
• Increasing fines (for example in The Netherlands €820,000
or 10% of annual net turnover)
• Amendments to introduce parts of GDPR in Belgium
• Privacy policy code in the UK
• CJEU right to be forgotten case (Dutch Regulator has
already investigated 111 RTBF cases up to May 2016)
@CorderyUK 26
© Cordery 2016
EU Cybersecurity Directive (NIS)
New EU Cybersecurity Directive
 Requires EU Member States to improve their national
cybersecurity capabilities and improve cooperation between
them on cybersecurity
 Businesses also affected - “operators of essential services”
and key “digital service providers” who will be required to:
- Assess the risks they face and adopt appropriate and
proportionate measures; and,
- Report to regulators major security incidents on their core
services - the “incidents” that will have to be reported are
broadly defined as “any event having an actual adverse
effect on the security of network and information systems.”
@CorderyUK 27
© Cordery 2016
Your response
1. Have an action plan
• Take a risk based approach
2. Have a proper data breach response plan;
3. Invest in proper technology;
4. Review vendor contracts – you will need their help to report
security breaches. Check you have the right contract with
them. Find vendors who know GDPR;
5. Put in place a DPIA process;
6. Get your documents and records ready to produce in a
regulatory inspection – factor this into overhead costs;
@CorderyUK 28
© Cordery 2016
Your response continued
7. Think of a world without employee consent and tougher
consent generally;
8. Make sure things like the right to be forgotten, the right to not
be subject to profiling are all covered in policies and
procedures;
9. Brief the Board and look at annual reporting requirements;
10. Train staff on all aspects of the law;
11. Set up and undertake regular compliance audits/reviews; and
12. Sense check your plans with specialist lawyers.
@CorderyUK 29
© Cordery 2016
Resources
• EU Cyber Security – www.bit.ly/eucyber
• New EU Data Rules – www.bit.ly/gdprfaqs
• Privacy Shield - http://www.corderycompliance.com/privacy-
shield-faqs/
• GDPR film – www.bit.ly/gdprfilm
• Right to be forgotten – http://bit.ly/1tB8Osb
• Cordery news – http://bit.ly/1vnFHJm
• Podcasts – www.bit.ly/techlaw10
• Weltimmo - http://www.corderycompliance.com/european-court-
weltimmo-ruling-on-the-jurisdiction-of-data-protection-
regulators/
• Mossack Fonseca - http://www.corderycompliance.com/mossack-
fonseca-panamaleaks-breach-has-significant-compliance-
consequences-for-most-businesses/
• LinkedIn – www.linkedin.com/in/jparmstrong
• What the Romans teach us about cybersecurity -
https://theanalogiesproject.org/the-analogies/romans-teach-us-
cybersecurity/
Questions
Cordery is a trading name of Cordery Compliance Limited. Authorised and regulated by the Solicitors Regulation Authority.
SRA number 608187. Company number 07931532 registered in England and Wales. VAT number: 730859520
Registered office: Lexis House, 30 Farringdon Street, London, EC4A 4HH, United Kingdom
Jonathan Armstrong
Cordery
jonathan.armstrong@corderycompliance.com
+44 (0)207 075 1784
www.twitter.com/armstrongjp

More Related Content

What's hot

ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
ESET
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
TrustArc
 
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTeEU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
TrustArc
 
1211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-161211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-16
jbauerofprivacy
 
SIA Webinar: The OHS Professional and Cyber Security
SIA Webinar: The OHS Professional and Cyber SecuritySIA Webinar: The OHS Professional and Cyber Security
SIA Webinar: The OHS Professional and Cyber Security
Australian Institute of Health & Safety
 
GDPR: More reasons for information security
GDPR: More reasons for information securityGDPR: More reasons for information security
GDPR: More reasons for information security
Jisc
 
GDPR compliance: getting everyone in the organisation on board
GDPR compliance: getting everyone in the organisation on boardGDPR compliance: getting everyone in the organisation on board
GDPR compliance: getting everyone in the organisation on board
IT Governance Ltd
 
Aon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber CriminalsAon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber Criminals
CSNP
 
Mbs r35 b
Mbs r35 bMbs r35 b
CASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disasterCASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disaster
B2B Marketing
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor Replacement
GACC_Midwest
 
The integration of legal aspects in Information Security: Is your organisatio...
The integration of legal aspects in Information Security: Is your organisatio...The integration of legal aspects in Information Security: Is your organisatio...
The integration of legal aspects in Information Security: Is your organisatio...
Rabelani Dagada
 
Legal issues on social media
Legal issues on social mediaLegal issues on social media
Legal issues on social media
Giulio Coraggio
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
Faidepro
 
Matthew Hough Clewes | Cyber Crime and its Impacts
Matthew Hough Clewes | Cyber Crime and its ImpactsMatthew Hough Clewes | Cyber Crime and its Impacts
Matthew Hough Clewes | Cyber Crime and its Impacts
Pro Mrkt
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your business
Eversheds Sutherland
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacy
GuyVanderSande
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
Karel Holst
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
Karel Holst
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
TrustArc
 

What's hot (20)

ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
 
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTeEU US Privacy Shield vs. GDPR Infographic from TRUSTe
EU US Privacy Shield vs. GDPR Infographic from TRUSTe
 
1211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-161211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-16
 
SIA Webinar: The OHS Professional and Cyber Security
SIA Webinar: The OHS Professional and Cyber SecuritySIA Webinar: The OHS Professional and Cyber Security
SIA Webinar: The OHS Professional and Cyber Security
 
GDPR: More reasons for information security
GDPR: More reasons for information securityGDPR: More reasons for information security
GDPR: More reasons for information security
 
GDPR compliance: getting everyone in the organisation on board
GDPR compliance: getting everyone in the organisation on boardGDPR compliance: getting everyone in the organisation on board
GDPR compliance: getting everyone in the organisation on board
 
Aon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber CriminalsAon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber Criminals
 
Mbs r35 b
Mbs r35 bMbs r35 b
Mbs r35 b
 
CASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disasterCASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disaster
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor Replacement
 
The integration of legal aspects in Information Security: Is your organisatio...
The integration of legal aspects in Information Security: Is your organisatio...The integration of legal aspects in Information Security: Is your organisatio...
The integration of legal aspects in Information Security: Is your organisatio...
 
Legal issues on social media
Legal issues on social mediaLegal issues on social media
Legal issues on social media
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
Matthew Hough Clewes | Cyber Crime and its Impacts
Matthew Hough Clewes | Cyber Crime and its ImpactsMatthew Hough Clewes | Cyber Crime and its Impacts
Matthew Hough Clewes | Cyber Crime and its Impacts
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your business
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacy
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
 

Similar to Ipswitch and cordery on the road " All you need to know about GDPR but are too afraid to ask "

Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
Lumension
 
Using international standards to improve EU cyber security
Using international standards to improve EU cyber securityUsing international standards to improve EU cyber security
Using international standards to improve EU cyber security
IT Governance Ltd
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
Richard Hogg,Global GDPR Offerings Evangelist
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
Iryna Chekanava
 
BDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEsBDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEs
Big Data Value Association
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
CIO Edge
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPR
IT Governance Ltd
 
CyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRCyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPR
Shadi A. Razak
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
Spoon London
 
Secure and Compliant Data Management in FinTech Applications
Secure and Compliant Data Management in FinTech ApplicationsSecure and Compliant Data Management in FinTech Applications
Secure and Compliant Data Management in FinTech Applications
Lionel Briand
 
GDPR Scotland 2018
GDPR Scotland 2018GDPR Scotland 2018
GDPR Scotland 2018
Ray Bugg
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
Adrian Dumitrescu
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
Agile PR
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
IT Governance Ltd
 
The Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and ProtectionThe Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and Protection
Atlas_Cloud
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Metering
nuances
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
IT Governance Ltd
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
Omo Osagiede
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
Richard Hogg,Global GDPR Offerings Evangelist
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
Napier University
 

Similar to Ipswitch and cordery on the road " All you need to know about GDPR but are too afraid to ask " (20)

Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
Using international standards to improve EU cyber security
Using international standards to improve EU cyber securityUsing international standards to improve EU cyber security
Using international standards to improve EU cyber security
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
 
BDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEsBDVe Webinar Series - Making GDPR for SMEs
BDVe Webinar Series - Making GDPR for SMEs
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPR
 
CyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPRCyNation - 7 things you should know about EU-GDPR
CyNation - 7 things you should know about EU-GDPR
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 
Secure and Compliant Data Management in FinTech Applications
Secure and Compliant Data Management in FinTech ApplicationsSecure and Compliant Data Management in FinTech Applications
Secure and Compliant Data Management in FinTech Applications
 
GDPR Scotland 2018
GDPR Scotland 2018GDPR Scotland 2018
GDPR Scotland 2018
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
 
The Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and ProtectionThe Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and Protection
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Metering
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 

Recently uploaded

Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Massimo Talia
 
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence LawyersDefending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
HarpreetSaini48
 
Business Laws Sunita saha
Business Laws Sunita sahaBusiness Laws Sunita saha
Business Laws Sunita saha
sunitasaha5
 
San Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at SeaSan Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at Sea
Justin Ordoyo
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
osenwakm
 
Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
MasoudZamani13
 
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
ssuser559494
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Syed Muhammad Humza Hussain
 
The Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in ItalyThe Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in Italy
BridgeWest.eu
 
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee
 
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
gjsma0ep
 
Search Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement OfficersSearch Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement Officers
RichardTheberge
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
ssusera97a2f
 
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdfV.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
bhavenpr
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
osenwakm
 
Receivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptxReceivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptx
Godwin Emmanuel Oyedokun MBA MSc PhD FCA FCTI FCNA CFE FFAR
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
MattGardner52
 
fnaf lore.pptx ...................................
fnaf lore.pptx ...................................fnaf lore.pptx ...................................
fnaf lore.pptx ...................................
20jcoello
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
lawyersonia
 
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
SKshi
 

Recently uploaded (20)

Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
 
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence LawyersDefending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
 
Business Laws Sunita saha
Business Laws Sunita sahaBusiness Laws Sunita saha
Business Laws Sunita saha
 
San Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at SeaSan Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at Sea
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
 
Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
 
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
 
The Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in ItalyThe Work Permit for Self-Employed Persons in Italy
The Work Permit for Self-Employed Persons in Italy
 
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
 
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
 
Search Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement OfficersSearch Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement Officers
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
 
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdfV.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
 
Receivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptxReceivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptx
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
 
fnaf lore.pptx ...................................
fnaf lore.pptx ...................................fnaf lore.pptx ...................................
fnaf lore.pptx ...................................
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
 
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
 

Ipswitch and cordery on the road " All you need to know about GDPR but are too afraid to ask "

  • 2. 1 IPSWITCH Paolo Ferrari Director, Solution Sales and Professional Services - EMEA, APAC and LATAM at Ipswitch, Inc. Sébastien Roques Regional Sales Manager Northern Europe at Ipswitch, Inc.
  • 3. 2
  • 4. 3 Jonathan Armstrong Jonathan is an experienced lawyer with a concentration on technology and compliance. His practice includes advising multinational companies on matters involving risk, compliance and technology across Europe. He has handled legal matters in more than 60 countries involving emerging technology, corporate governance, ethics code implementation, reputation, internal investigations, marketing, branding and global privacy policies
  • 5. Why are we here today ?
  • 6. 5 World’s biggest data breaches In 2015. Showing losses over 30.000 records and up.
  • 8.
  • 9. 8 2016 State of Data Security and Compliance
  • 11. 10 Ipswitch Company Overview Company Overview • Founded 1991 • Headquarters: Lexington, MA • Remote Offices: • Alpharetta, GA • Madison, WI • Heidelberg, Germany • 300 Employees Financials • Privately Held • Revenues of $76M+ in 2015 • Over 55% Recurring Revenue • Over 50% of Revenues from Indirect Channel • 30% from International • Double Digit EBITDA Margin • No Debt Customer Overview • 25,000+ Active customers • Across 168 countries • Present in a wide array of industry verticals • Strong renewal rates on both product lines
  • 12. 11 One Ipswitch: 2 minute company overview
  • 13. 12 LARGE AND THRIVING CUSTOMER BASE Over 25,000 Global SMB, Government & Enterprise Customers SECURE CONTROL of Business Transactions, Applications and Infrastructure CORE PRODUCT LINES IT and Network Monitoring Secure Information and File Transfer The Pioneer in EASY TO TRY, BUY AND USE IT Management Software 2 Option 2 Ipswitch at a Glance
  • 14. 13 MOVEit Managed File Transfer WS_FTP Secure File Transfer MessageWay B2B File Transfer and Integration Ipswitch Analytics SLA and Compliance Analytics WhatsUp Gold Unified Network, Server & App Monitoring Event & Log Management Collects, store and analyze log files AlertFox Web Performance Monitoring Secure Information and File Transfer Ipswitch Products IT Monitoring and Management
  • 15. 25,000+ active customers in 116 countries
  • 16. All you need to know about GDPR but are too afraid to ask... 12 October 2016 Jonathan Armstrong
  • 17. @CorderyUK 16 © Cordery 2016 Data Security - Landscape • Personal data has a value • Different political reactions • Different legal systems worldwide • Different enforcement even within Europe • Contrasting approach Europe -v- US • Snowden has changed the game • Schrems has had a real impact • GDPR already a reality
  • 18. © Cordery 2016 17 Current UK Legislative background “Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.”
  • 19. @CorderyUK 18 © Cordery 2016 Section 13 of the Dutch Personal Data Protection Act “The controller implements appropriate technical and organisational measures to protect personal data against loss or any unlawful forms of processing. Having regard to the state of the art and the cost of their implementation, such measures will guarantee a level of security appropriate to the risks represented by the processing and the nature of the data to be protected. These measures also seek to prevent the unnecessary collection and further processing of personal data.” * unofficial translation
  • 20. @CorderyUK 19 © Cordery 2016 Example: South Wales Police • South Wales Police had sensitive films from victims • They recorded the interviews • They moved the videos between offices, courts etc. on DVD • The DVDs were encrypted & stored in a desk drawer • The DVDs were lost after an office move although the loss was not reported for two years • Victim made a formal complaint • Prosecution prejudiced • ICO fined South Wales Police £160,000
  • 21. @CorderyUK 20 © Cordery 2016 Prevention Dutch AP: “Contingency plan Every organisation should have a contingency plan indicating exactly what is to happen in the event of an emergency. However, such a plan is useful only if personnel are familiar with it and regular drills have been held to practise its implementation...”
  • 22. @CorderyUK 21 © Cordery 2016 New EU data rules • A = aims • B = benefits • C = consequences
  • 23. @CorderyUK 22 © Cordery 2016 New EU data rules - Aims • Proposed Regulation not Directive (but with carve-outs) • Data protection by design/default • Data Protection Impact Assessments (aka PIAs) • Suppliers outside EU in scope • Toughened (local not centralised) enforcement bodies - audits & dawn raids • Breach reporting in 72 hours • Distinction between processor and controller diminishes • Data Protection Officers • Transfers to 3rd countries - Binding Corporate Rules
  • 24. @CorderyUK 23 © Cordery 2016 New EU data rules - Benefits • No general registration requirement? • One stop shop? • Consent less of an option? • Right to be forgotten? • Right to portability? • Right to object to profiling? • Enhanced SAR Regime?
  • 25. @CorderyUK 24 © Cordery 2016 New EU data rules - Consequences • More to do for controllers and processors • Liability & compensation (material or non-material damage) • Fines of up to 4% of global annual turnover • Shared investigations across the EU • Greater reputational risk • Shareholder/investor engagement
  • 26. @CorderyUK 25 © Cordery 2016 GDPR already a reality • Data breach reporting laws in Germany, Austria and The Netherlands (but not identical to GDPR) • Usually a notification in The Netherlands to the AP must be done “immediately” and in any case within 72 hours – AP received 1,500+ notifications in first four months, c.70 regulatory actions • Increasing fines (for example in The Netherlands €820,000 or 10% of annual net turnover) • Amendments to introduce parts of GDPR in Belgium • Privacy policy code in the UK • CJEU right to be forgotten case (Dutch Regulator has already investigated 111 RTBF cases up to May 2016)
  • 27. @CorderyUK 26 © Cordery 2016 EU Cybersecurity Directive (NIS) New EU Cybersecurity Directive  Requires EU Member States to improve their national cybersecurity capabilities and improve cooperation between them on cybersecurity  Businesses also affected - “operators of essential services” and key “digital service providers” who will be required to: - Assess the risks they face and adopt appropriate and proportionate measures; and, - Report to regulators major security incidents on their core services - the “incidents” that will have to be reported are broadly defined as “any event having an actual adverse effect on the security of network and information systems.”
  • 28. @CorderyUK 27 © Cordery 2016 Your response 1. Have an action plan • Take a risk based approach 2. Have a proper data breach response plan; 3. Invest in proper technology; 4. Review vendor contracts – you will need their help to report security breaches. Check you have the right contract with them. Find vendors who know GDPR; 5. Put in place a DPIA process; 6. Get your documents and records ready to produce in a regulatory inspection – factor this into overhead costs;
  • 29. @CorderyUK 28 © Cordery 2016 Your response continued 7. Think of a world without employee consent and tougher consent generally; 8. Make sure things like the right to be forgotten, the right to not be subject to profiling are all covered in policies and procedures; 9. Brief the Board and look at annual reporting requirements; 10. Train staff on all aspects of the law; 11. Set up and undertake regular compliance audits/reviews; and 12. Sense check your plans with specialist lawyers.
  • 30. @CorderyUK 29 © Cordery 2016 Resources • EU Cyber Security – www.bit.ly/eucyber • New EU Data Rules – www.bit.ly/gdprfaqs • Privacy Shield - http://www.corderycompliance.com/privacy- shield-faqs/ • GDPR film – www.bit.ly/gdprfilm • Right to be forgotten – http://bit.ly/1tB8Osb • Cordery news – http://bit.ly/1vnFHJm • Podcasts – www.bit.ly/techlaw10 • Weltimmo - http://www.corderycompliance.com/european-court- weltimmo-ruling-on-the-jurisdiction-of-data-protection- regulators/ • Mossack Fonseca - http://www.corderycompliance.com/mossack- fonseca-panamaleaks-breach-has-significant-compliance- consequences-for-most-businesses/ • LinkedIn – www.linkedin.com/in/jparmstrong • What the Romans teach us about cybersecurity - https://theanalogiesproject.org/the-analogies/romans-teach-us- cybersecurity/
  • 31. Questions Cordery is a trading name of Cordery Compliance Limited. Authorised and regulated by the Solicitors Regulation Authority. SRA number 608187. Company number 07931532 registered in England and Wales. VAT number: 730859520 Registered office: Lexis House, 30 Farringdon Street, London, EC4A 4HH, United Kingdom Jonathan Armstrong Cordery jonathan.armstrong@corderycompliance.com +44 (0)207 075 1784 www.twitter.com/armstrongjp