SlideShare a Scribd company logo
1 of 1
KEY	CHANGES	INTRODUCED	BY	GENERAL	DATA	PROTECTION	REGULATION	
	
Policies	
	
•  Update	Terms	and	Condi0ons	on	all	agreements	with	Suppliers	(Data	Processors	and	
Customers	(agreements,	digital	assets,	apps	etc.)	
•  Update	Consent	Clauses	
•  Update	Data	Privacy	No0ces	
•  Update	3	Lines	of	Defense	model	and	Data	Privacy	Frameworks	for	new	roles	
•  Amend	Data	Privacy	Policy	for	changes	introduced	by	GDPR	
•  New	Product	/	Process	/	Systems	to	incorporate	GDPR	requirements	by	design	
	
Teams	
	
•  Introduce	new	role	for	a	Data	Protec0on	Officer	working	independently	of	business		
	
Processes	
	
•  Upgrade	Consent	Collec0on	
•  Introduce	Data	Request	Management	
•  Add	Review	of	Data	Processor	
•  Build	Privacy	Impact	Assessment	(Risk	Appe0te	and	Assessment)	
•  Create	Breach	No0fica0on	Process	within	72	
	
Systems	
	
•  Website	cookie	updates	based	on	the	new	privacy	policy	
•  Automa0c	Breach	No0fica0on	+	Automa0c	Right	to	be	ForgoVen	management	system	
which	can	be	linked	to	Privacy	Impact	Assessment	(this	will	have	to	be	matured	in	an	
agile	fashion	by	building	a	Proof	of	Concept	for	sample	data	assets	and	subjects,	extend	
to	Minimum	Viable	Product	with	key	features	and	extend	to	strategic	versions	aZer	the	
success	of	MVP)	
GDPR	extends	the	scope	to	foreign	companies	processing	data	of	EU	residents	and	harmonizes	the	data	protec0on	regula0on	throughout	EU.	It	replaces	
EU	Data	Protec0on	Direc0ve	(95/46/EC),	which	required	member	states	to	achieve	data	protec0on	without	enforcing	means.	The	2	broad	changes	are	
accountability	(to	be	able	to	demonstrate	compliance)	and	data	protec0on	by	design.	Non-compliance	can	lead	upto	fines	of	4%	of	annual	global	
turnover.	
Increased	territorial	scope	
	
GDPR	regime	extends	scope	to	all	companies	processing	the	
personal	data	of	EU	residents,	regardless	of	the	company’s	
loca0on.	
	
Explicit	and	retractable	consent	
	
All	personal	data	must	only	processed	if	there	is	a	lawful	basis	for	
it	and	a	specific,	intelligible	and	easily	accessible	consent	must	be	
provided	by	data	subject	in	accessible	form.	It	must	be	as	easy	to	
withdraw	consent	as	it	is	to	give.		
Right	to	access	and	portability	
	
Data	subjects	can	request	confirma0on	as	to	whether	or	not	
personal	data	concerning	them	is	being	processed,	where	and	for	
what	purpose.	Further,	the	controller	shall	provide	a	copy	of	the	
personal	data,	free	of	charge,	in	an	electric	format.	
Mandatory	Data	ProtecGon	Officer	
	
Appointed	in	certain	cases	(public	authori0es,	when	monitoring	of	
data	subjects	on	a	large	scale	and	when	processing	special	
categories	of	data).	To	facilitate	the	need	for	a	company	to	
demonstrate	their	compliance	to	the	GDPR	and	compensate	for	
GDPR	no	longer	requiring	the	bureaucra0c	submission	of	
no0fica0ons/registra0ons	of	data	processing	ac0vi0es	or	transfers	
based	on	Model	Contract	Clauses.	
Right	to	be	forgoJen	
	
En0tles	the	data	subject	to	have	the	data	controller	erase	his/her	
personal	data,	cease	further	dissemina0on	of	the	data,	and	
poten0ally	have	third	par0es	halt	processing	of	the	data	
SUGGESTED	CHANGES	TO	OPERATING	MODEL

More Related Content

What's hot

Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyRob Johnston, MBA
 
ESRA December 2018
ESRA December 2018ESRA December 2018
ESRA December 2018Mimecast
 
Successful Implementation of Compliance Builder for a Global Leader
Successful Implementation of Compliance Builder for a Global LeaderSuccessful Implementation of Compliance Builder for a Global Leader
Successful Implementation of Compliance Builder for a Global LeaderXybion Corporation
 
digitalenergy meter solutions
digitalenergy meter solutionsdigitalenergy meter solutions
digitalenergy meter solutionsAlun Thomas
 
Supply Chain with Cost Optimization Flyer
Supply Chain with Cost Optimization FlyerSupply Chain with Cost Optimization Flyer
Supply Chain with Cost Optimization FlyerDan Ahearn
 
Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...
Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...
Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...Yokogawa1
 
Product reengineering solution for a global web services enterprise.
Product reengineering solution for a global web services enterprise.Product reengineering solution for a global web services enterprise.
Product reengineering solution for a global web services enterprise.Mindtree Ltd.
 
Regulatory Reporting Simplification
Regulatory Reporting SimplificationRegulatory Reporting Simplification
Regulatory Reporting SimplificationVarun Mittal
 
Buildwave BCLM/Violog Overview
Buildwave BCLM/Violog OverviewBuildwave BCLM/Violog Overview
Buildwave BCLM/Violog Overviewjzurawski
 

What's hot (9)

Adaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_studyAdaptive grc life_sciences_case_study
Adaptive grc life_sciences_case_study
 
ESRA December 2018
ESRA December 2018ESRA December 2018
ESRA December 2018
 
Successful Implementation of Compliance Builder for a Global Leader
Successful Implementation of Compliance Builder for a Global LeaderSuccessful Implementation of Compliance Builder for a Global Leader
Successful Implementation of Compliance Builder for a Global Leader
 
digitalenergy meter solutions
digitalenergy meter solutionsdigitalenergy meter solutions
digitalenergy meter solutions
 
Supply Chain with Cost Optimization Flyer
Supply Chain with Cost Optimization FlyerSupply Chain with Cost Optimization Flyer
Supply Chain with Cost Optimization Flyer
 
Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...
Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...
Foundation, Transition, Transform – Koch’s Journey Toward The Plant of the Fu...
 
Product reengineering solution for a global web services enterprise.
Product reengineering solution for a global web services enterprise.Product reengineering solution for a global web services enterprise.
Product reengineering solution for a global web services enterprise.
 
Regulatory Reporting Simplification
Regulatory Reporting SimplificationRegulatory Reporting Simplification
Regulatory Reporting Simplification
 
Buildwave BCLM/Violog Overview
Buildwave BCLM/Violog OverviewBuildwave BCLM/Violog Overview
Buildwave BCLM/Violog Overview
 

Similar to Key Operating Model Changes due to GDPR

Biz Talk Demo slideshare
Biz Talk Demo slideshareBiz Talk Demo slideshare
Biz Talk Demo slideshareerios
 
Firehost Webinar: Getting Ready for PCI 3.0
Firehost Webinar: Getting Ready for PCI 3.0Firehost Webinar: Getting Ready for PCI 3.0
Firehost Webinar: Getting Ready for PCI 3.0Armor
 
Taking the fire drill out of making firewall changes
Taking the fire drill out of making firewall changesTaking the fire drill out of making firewall changes
Taking the fire drill out of making firewall changesAlgoSec
 
BA Agile Decision Management - Impact 2010
BA Agile Decision Management - Impact 2010BA Agile Decision Management - Impact 2010
BA Agile Decision Management - Impact 2010Richard Buchanan
 
Loftware UDI Webinar 1
Loftware UDI Webinar 1Loftware UDI Webinar 1
Loftware UDI Webinar 1Loftware
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...D. Scott Clark
 
Test scenario preparation_approach_document & estimates
Test scenario preparation_approach_document & estimatesTest scenario preparation_approach_document & estimates
Test scenario preparation_approach_document & estimatesvishalbali0
 
Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...
Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...
Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...Precisely
 
Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day Martin Thompson
 
SOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted AccountingSOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted AccountingRoseASP
 
Toreon adding privacy by design in secure application development oss18 v20...
Toreon adding privacy by design in secure application development   oss18 v20...Toreon adding privacy by design in secure application development   oss18 v20...
Toreon adding privacy by design in secure application development oss18 v20...Sebastien Deleersnyder
 
Subscribed 2015: The Explosion of Smart Connected Things
Subscribed 2015: The Explosion of Smart Connected ThingsSubscribed 2015: The Explosion of Smart Connected Things
Subscribed 2015: The Explosion of Smart Connected ThingsZuora, Inc.
 
GDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsGDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsRevulytics Inc.
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Cloud Standards Customer Council
 
Oracle Insurance ERP.ppt
Oracle Insurance ERP.pptOracle Insurance ERP.ppt
Oracle Insurance ERP.pptJd Ash
 

Similar to Key Operating Model Changes due to GDPR (20)

Biz Talk Demo slideshare
Biz Talk Demo slideshareBiz Talk Demo slideshare
Biz Talk Demo slideshare
 
Firehost Webinar: Getting Ready for PCI 3.0
Firehost Webinar: Getting Ready for PCI 3.0Firehost Webinar: Getting Ready for PCI 3.0
Firehost Webinar: Getting Ready for PCI 3.0
 
Taking the fire drill out of making firewall changes
Taking the fire drill out of making firewall changesTaking the fire drill out of making firewall changes
Taking the fire drill out of making firewall changes
 
BA Agile Decision Management - Impact 2010
BA Agile Decision Management - Impact 2010BA Agile Decision Management - Impact 2010
BA Agile Decision Management - Impact 2010
 
Loftware UDI Webinar 1
Loftware UDI Webinar 1Loftware UDI Webinar 1
Loftware UDI Webinar 1
 
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...GLOBAL LIFE SCIENCES COMPANY USES  ADAPTIVEGRC SUITE  TO MANAGE RISK & COMPLI...
GLOBAL LIFE SCIENCES COMPANY USES ADAPTIVEGRC SUITE TO MANAGE RISK & COMPLI...
 
Test scenario preparation_approach_document & estimates
Test scenario preparation_approach_document & estimatesTest scenario preparation_approach_document & estimates
Test scenario preparation_approach_document & estimates
 
Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...
Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...
Maximize ROI of Insurance Digital Transformation Initiatives with Proven Data...
 
Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day Concorde Solutions ITAM Review Tools Day
Concorde Solutions ITAM Review Tools Day
 
Cloud Navigator
Cloud NavigatorCloud Navigator
Cloud Navigator
 
SOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted AccountingSOX Cloud Criteria Cloud Hosted Accounting
SOX Cloud Criteria Cloud Hosted Accounting
 
Forecast 2014: SaaS Data Exchange
Forecast 2014: SaaS Data ExchangeForecast 2014: SaaS Data Exchange
Forecast 2014: SaaS Data Exchange
 
Jon shende fbcs citp q&a
Jon shende fbcs citp q&aJon shende fbcs citp q&a
Jon shende fbcs citp q&a
 
Toreon adding privacy by design in secure application development oss18 v20...
Toreon adding privacy by design in secure application development   oss18 v20...Toreon adding privacy by design in secure application development   oss18 v20...
Toreon adding privacy by design in secure application development oss18 v20...
 
PC
PCPC
PC
 
PC
PCPC
PC
 
Subscribed 2015: The Explosion of Smart Connected Things
Subscribed 2015: The Explosion of Smart Connected ThingsSubscribed 2015: The Explosion of Smart Connected Things
Subscribed 2015: The Explosion of Smart Connected Things
 
GDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage AnalyticsGDPR Readiness for Software Usage Analytics
GDPR Readiness for Software Usage Analytics
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
 
Oracle Insurance ERP.ppt
Oracle Insurance ERP.pptOracle Insurance ERP.ppt
Oracle Insurance ERP.ppt
 

Recently uploaded

WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
How to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfHow to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfdanishmna97
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringWSO2
 
ADP Passwordless Journey Case Study.pptx
ADP Passwordless Journey Case Study.pptxADP Passwordless Journey Case Study.pptx
ADP Passwordless Journey Case Study.pptxFIDO Alliance
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxRemote DBA Services
 
Top 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development CompaniesTop 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development CompaniesTopCSSGallery
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Bhuvaneswari Subramani
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
الأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهلهالأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهلهMohamed Sweelam
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityWSO2
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)Samir Dash
 
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....rightmanforbloodline
 
Navigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseNavigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseWSO2
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontologyjohnbeverley2021
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 

Recently uploaded (20)

WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
How to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfHow to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cf
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software Engineering
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
ADP Passwordless Journey Case Study.pptx
ADP Passwordless Journey Case Study.pptxADP Passwordless Journey Case Study.pptx
ADP Passwordless Journey Case Study.pptx
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Top 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development CompaniesTop 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development Companies
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
الأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهلهالأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهله
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
 
Navigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseNavigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern Enterprise
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 

Key Operating Model Changes due to GDPR

  • 1. KEY CHANGES INTRODUCED BY GENERAL DATA PROTECTION REGULATION Policies •  Update Terms and Condi0ons on all agreements with Suppliers (Data Processors and Customers (agreements, digital assets, apps etc.) •  Update Consent Clauses •  Update Data Privacy No0ces •  Update 3 Lines of Defense model and Data Privacy Frameworks for new roles •  Amend Data Privacy Policy for changes introduced by GDPR •  New Product / Process / Systems to incorporate GDPR requirements by design Teams •  Introduce new role for a Data Protec0on Officer working independently of business Processes •  Upgrade Consent Collec0on •  Introduce Data Request Management •  Add Review of Data Processor •  Build Privacy Impact Assessment (Risk Appe0te and Assessment) •  Create Breach No0fica0on Process within 72 Systems •  Website cookie updates based on the new privacy policy •  Automa0c Breach No0fica0on + Automa0c Right to be ForgoVen management system which can be linked to Privacy Impact Assessment (this will have to be matured in an agile fashion by building a Proof of Concept for sample data assets and subjects, extend to Minimum Viable Product with key features and extend to strategic versions aZer the success of MVP) GDPR extends the scope to foreign companies processing data of EU residents and harmonizes the data protec0on regula0on throughout EU. It replaces EU Data Protec0on Direc0ve (95/46/EC), which required member states to achieve data protec0on without enforcing means. The 2 broad changes are accountability (to be able to demonstrate compliance) and data protec0on by design. Non-compliance can lead upto fines of 4% of annual global turnover. Increased territorial scope GDPR regime extends scope to all companies processing the personal data of EU residents, regardless of the company’s loca0on. Explicit and retractable consent All personal data must only processed if there is a lawful basis for it and a specific, intelligible and easily accessible consent must be provided by data subject in accessible form. It must be as easy to withdraw consent as it is to give. Right to access and portability Data subjects can request confirma0on as to whether or not personal data concerning them is being processed, where and for what purpose. Further, the controller shall provide a copy of the personal data, free of charge, in an electric format. Mandatory Data ProtecGon Officer Appointed in certain cases (public authori0es, when monitoring of data subjects on a large scale and when processing special categories of data). To facilitate the need for a company to demonstrate their compliance to the GDPR and compensate for GDPR no longer requiring the bureaucra0c submission of no0fica0ons/registra0ons of data processing ac0vi0es or transfers based on Model Contract Clauses. Right to be forgoJen En0tles the data subject to have the data controller erase his/her personal data, cease further dissemina0on of the data, and poten0ally have third par0es halt processing of the data SUGGESTED CHANGES TO OPERATING MODEL