SlideShare a Scribd company logo
1
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Six Steps to GDPR
Readiness
Is Your Organization Ready for the
General Data Protection Regulation?
Jonathan Adams, Research Director
GDPR
2
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Peter Steiner; New Yorker Magazine; July 1993
3
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR3 Reasons to Care
4
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
1. Reduce Costs
Fines up to 4% of Global Revenue
*2016 Annual Revenues
5
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
2. Increase Margins
GDPR Capabilities support digital transformation goals and drive
new business models:
• Consumer
Centric PLM
• Supply Chain &
Channel
Optimization
• Customer 360
programs
6
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
3. Grow Revenue
Data Monetization &
New Revenue Streams
• Sports “Wearables”
• Self Identification at POI
• Cloud Based Services
“Trust” with Partners
& Customers
7
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
The Clock is Ticking…
8
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Defining GDPR
GDPR is a comprehensive set of privacy regulations designed to protect data for individuals
within the European Union.
Objective:
• Give individuals control of their personal data
• Regulatory consistency across the EU
Impact:
• Covers personal data collected in EU regardless of where the data
collector is located
• All US based multi nationals doing business with people in Europe
will be impacted
9
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR’s Impact on Companies
Any business (foreign or domestic) engaged with individuals within the EU
The notion of Personal Information (PI) is broadly defined: data that has the
potential to identify a person living in Europe falls under the GDPR
GDPR applies “horizontally” across the organization’s business components,
and “vertically” at all decision making levels.
GDPR applies across the complete value chain. Organizations are obligated to
verify the compliance of parties with which they do business.
10
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR Requires Interpretation
General Data
Protection Regulation
11
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR Requires Interpretation
It’s Comprehensive & Tightly Written
• All personal information regardless of where it came from and how it is used is governed
It’s Principle Based
• Requires companies to adopt privacy principles at the cultural level
It’s Compromise Legislation
• GDPR is a piece of what legal scholars call compromise legislation: a legislative text that tries to
satisfy two starkly opposed sides of the data protection debate
When Interpretation is Required, Best Practices are Critical
12
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
The Governance Challenge
Creating transparent &
defensible best practices
that address “principles”
13
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Risk
Management
Accountability
Org Design
Data Lineage
Process
Alignment
PII Cataloging International
Partner
Management
Metadata
Data
Governance
Data
Architecture
Data
Operations
Data Discovery
Best Practices
Security
Data
Management
Privacy
Cloud Services
IoT
The Governance Challenge
Mapping the best practices to observable & measurable
activities across many functional areas
Processes
Objectives
Standards
Metrics
Data
Rules
14
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
The 4 Core Capabilities
GDPR requirements can be simplified by
organizing around four core capability areas:
Consultation
& Reporting
• Certification
• Risk Management
• Organizational
Alignment
• Privacy by Design
• Risk Management
• Communication
• Remediation
• People
• Partners
• Regulators
• Organization
15
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
People: The “owners” of Personal Information
Forget
Quarantine
Package
Fix
Consent
Notification
Access
• Greater detail and clarity is
called for when collecting
data
• Consent must be explicit as
to use of data, how it will be
processed, and by whom
• Notification of breach is
required (within 72 hours to
the regulator)
Under GDPR Individuals
have the following rights:
• To be Informed
• To Access
• To Rectify
• To Erasure
• To Restrict Processing
• To Data Portability
• To Object
• Related to automated
Decision Making and
Profiling
Obligations Rights
16
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Organization: “Data Protection by Design”
Data
Management
International
Best Practices
Risk
Management
Accountability
Obligations
• Accountability – vertically, horizontally and
externally
• Data Protection Officer required for most
large companies
• Best practice “Codes of Conduct” mitigate
against enforcement action
• Assessment of risk will drive multiple
decisions – it needs to be transparent and
defensible
• Cross border data exchanges do not obviate
requirements
17
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Partners: A New Risk Dimension
Certification
Risk
Management
Processor
Compliance
Obligations
• Transfers of Personal Information between your
company and business partners does not transfer
the responsibility to ensure it is safeguarded – it is
still yours to look after
• Establish a way to ensure your partners are
providing GDPR level security
• Best practices certifications that support third
party audits will streamline assessment process
and mitigate risk
• Due diligence and transparency is key to
demonstrating diligence
18
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Regulators: Communication is key
Consultation
Best Practices
Obligations
• Notification is required in the event of a breach
• “Breach” is broadly defined: destruction, loss,
alteration, unauthorized disclosure of, or access
to, personal data
• Reporting to regulators within 72 hours when
breach is likely to result in a risk to the rights and
freedoms of individuals
• “Prior Consultation” is an expectation
• Privacy Impact Assessment anchors the regulator
and risk discussions
• Best Practices will streamline these discussions
19
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR6 Steps to Readiness
20
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
1. Readiness Baseline
Compliance Capability Readiness=+
Do the Right Thing – Do it Right!
Understand Where You Are
21
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
2. Best Practices
Aligning to Recognized Best Practice Frameworks Mitigates Risk
2 Talk the Talk – Walk the Walk
3 Promote within Industry Associations
Pick a Framework That Works for You1
Understand How You Want to Manage
22
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
What is my GDPR Related Data?
23
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
3. Catalog
“To understand yourself is the beginning of wisdom.” – Krishnamaurti
2 Catalog Data: Foundational to Managing Data
3 Describe Data: Tag to Answer Compliance
Requirements
Identify Data: PI; Sensitive; Packaged; Erasable1
Understand What You are Managing
24
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Who is in charge? Why is this information valuable? And what is the impact of a privacy breach?
Why Do I Have It; How Is It Used?
25
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
4. Data Lifecycle
Where Is It and How Is It Used?
Lineage is a challenge!
• E-commerce sites
• Marketing functions
• Shipping fulfillment
• CRM
Start with known
Business
Functions
Focus on Core
Requirements
• Consent
• Notification
• Remediation
• Partner Management
26
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
5. Build Risk Capabilities
Defensible; Transparent; Demonstrable
Vulnerabilities
17-2
32-1
32-2
33-1
33-3
34-1
GDPR
Risk
Areas
34-3
35-1
35-7-c,d
35-11
49-1-a
Practices
Mitigation
RiskGovernance
Risk Analysis &
Metrics
“To [the] rights
and freedoms of
natural persons”
27
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Am I Ready For the Regulators?
28
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
6. Governance Framework
Operating
Model
Organizational
Alignment
Mobilizing Cross-
Functional Teams
Empowerment
(with Rules and
Tools)
Outcome focused
Metrics
Ownership &
Accountability
Step-Change
Change Management
Pulling it all Together!
29
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPRQuestions?
Jonathan Adams; 443-223-2534
jonathan.adams@datumstrategy.com
30
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Some Useful Links
Whitepapers
• GDPR Guide: 3 Steps to Readiness: http://info.datumstrategy.com/gdpr-guide-ebook-paper-privacy-compliance
Blogs
• Will the Privacy Shield Protect You? http://www.datumstrategy.com/blog/will-the-privacy-shield-protect-you
• 7 Key GDPR Requirements & the Role of Data Governance: http://www.datumstrategy.com/blog/gdpr-requirements-and-data-
governance
• What’s GDPR and the Penalty for Not Complying? http://www.datumstrategy.com/blog/what-is-gdpr-fines-penalties-for-not-
complying
Websites
• GDPR Portal: http://www.eugdpr.org
• DATUM Strategy: http://www.datumstrategy.com
Informative Sites:
• The UK Information Commissioner’s Office (ICO) has a well put together site that makes it easy to find answers:
https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/
• The Linklaters Law Firm has a number of resource papers (versus marketing papers): The General Data Protection Regulation:
A Survival Guide; and A report on global data protection laws in 2016.
https://clientsites.linklaters.com/Clients/dataprotected/Pages/TheGDPR.aspx
• The book by Chiara Rustici: Applying the GDPR: Privacy Rules For The Data Economy is very informative. Pre-release is out
http://shop.oreilly.com/product/0636920055723.do

More Related Content

What's hot

Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
Dr. Sami Zahran
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
Paul O'Carroll
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
Zymplify
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
Microsoft Österreich
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
Ulf Mattsson
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
Harrison Clark Rickerbys
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
Kyle Davies
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
IDERA Software
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
Ulf Mattsson
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
Ulf Mattsson
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
HackerOne
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
DATAVERSITY
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
Vicky Dallas
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
Zoodikers
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity Legislation
IBM Security
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
DATUM LLC
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
Naomi Holmes
 
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
DATUM LLC
 

What's hot (20)

Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity Legislation
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
 

Similar to Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regulations

Enterprise Data World 2018
Enterprise Data World 2018Enterprise Data World 2018
Enterprise Data World 2018
jadams6
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Software Integrity Group
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?
Gareth Miller
 
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM WorksGDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
BCS Data Management Specialist Group
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
DATUM LLC
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
InfoGoTo
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
SecurityScorecard
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
accenture
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
accenture
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
Maddie Malling-May
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
Olivier BARROT
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected Data
Neo4j
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
Match-Maker Ventures
 
Symantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR ComplianceSymantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR Compliance
Symantec
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
Exponential_e
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
accenture
 
3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.
Richard Kranendonk
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
Integrate
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
CIO Edge
 
13687562.ppt
13687562.ppt13687562.ppt
13687562.ppt
handywicaksono2
 

Similar to Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regulations (20)

Enterprise Data World 2018
Enterprise Data World 2018Enterprise Data World 2018
Enterprise Data World 2018
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?
 
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM WorksGDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected Data
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
Symantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR ComplianceSymantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR Compliance
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
 
3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
13687562.ppt
13687562.ppt13687562.ppt
13687562.ppt
 

More from DATUM LLC

The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?
DATUM LLC
 
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DATUM LLC
 
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
DATUM LLC
 
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
DATUM LLC
 
Business KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for HersheyBusiness KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for Hershey
DATUM LLC
 
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics 5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
DATUM LLC
 
Data Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk DownData Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk Down
DATUM LLC
 
5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital Transformation5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital Transformation
DATUM LLC
 
5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANA5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANA
DATUM LLC
 
14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy Statistics14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy Statistics
DATUM LLC
 
3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...
DATUM LLC
 
How JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANAHow JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANA
DATUM LLC
 
9 Funny Data "Fails"
9 Funny Data "Fails" 9 Funny Data "Fails"
9 Funny Data "Fails"
DATUM LLC
 
How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model
DATUM LLC
 

More from DATUM LLC (14)

The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?
 
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
 
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
 
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
 
Business KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for HersheyBusiness KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for Hershey
 
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics 5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
 
Data Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk DownData Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk Down
 
5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital Transformation5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital Transformation
 
5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANA5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANA
 
14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy Statistics14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy Statistics
 
3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...
 
How JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANAHow JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANA
 
9 Funny Data "Fails"
9 Funny Data "Fails" 9 Funny Data "Fails"
9 Funny Data "Fails"
 
How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model
 

Recently uploaded

Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
Opendatabay
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
nscud
 
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
vcaxypu
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
enxupq
 
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
slg6lamcq
 
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
axoqas
 
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
pchutichetpong
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP
 
Adjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTESAdjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTES
Subhajit Sahu
 
社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .
NABLAS株式会社
 
Q1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year ReboundQ1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year Rebound
Oppotus
 
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
axoqas
 
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdfSample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Linda486226
 
一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单
ewymefz
 
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
ewymefz
 
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Subhajit Sahu
 
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
ewymefz
 
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
ukgaet
 
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
John Andrews
 
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdfCh03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
haila53
 

Recently uploaded (20)

Opendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptxOpendatabay - Open Data Marketplace.pptx
Opendatabay - Open Data Marketplace.pptx
 
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
一比一原版(CBU毕业证)卡普顿大学毕业证成绩单
 
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
一比一原版(ArtEZ毕业证)ArtEZ艺术学院毕业证成绩单
 
一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单一比一原版(QU毕业证)皇后大学毕业证成绩单
一比一原版(QU毕业证)皇后大学毕业证成绩单
 
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
一比一原版(Adelaide毕业证书)阿德莱德大学毕业证如何办理
 
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
哪里卖(usq毕业证书)南昆士兰大学毕业证研究生文凭证书托福证书原版一模一样
 
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
Data Centers - Striving Within A Narrow Range - Research Report - MCG - May 2...
 
Criminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdfCriminal IP - Threat Hunting Webinar.pdf
Criminal IP - Threat Hunting Webinar.pdf
 
Adjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTESAdjusting primitives for graph : SHORT REPORT / NOTES
Adjusting primitives for graph : SHORT REPORT / NOTES
 
社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .社内勉強会資料_LLM Agents                              .
社内勉強会資料_LLM Agents                              .
 
Q1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year ReboundQ1’2024 Update: MYCI’s Leap Year Rebound
Q1’2024 Update: MYCI’s Leap Year Rebound
 
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
做(mqu毕业证书)麦考瑞大学毕业证硕士文凭证书学费发票原版一模一样
 
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdfSample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
Sample_Global Non-invasive Prenatal Testing (NIPT) Market, 2019-2030.pdf
 
一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单一比一原版(NYU毕业证)纽约大学毕业证成绩单
一比一原版(NYU毕业证)纽约大学毕业证成绩单
 
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
一比一原版(UPenn毕业证)宾夕法尼亚大学毕业证成绩单
 
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
Levelwise PageRank with Loop-Based Dead End Handling Strategy : SHORT REPORT ...
 
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
一比一原版(UofM毕业证)明尼苏达大学毕业证成绩单
 
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
一比一原版(UVic毕业证)维多利亚大学毕业证成绩单
 
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
Chatty Kathy - UNC Bootcamp Final Project Presentation - Final Version - 5.23...
 
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdfCh03-Managing the Object-Oriented Information Systems Project a.pdf
Ch03-Managing the Object-Oriented Information Systems Project a.pdf
 

Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regulations

  • 1. 1 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Six Steps to GDPR Readiness Is Your Organization Ready for the General Data Protection Regulation? Jonathan Adams, Research Director GDPR
  • 2. 2 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Peter Steiner; New Yorker Magazine; July 1993
  • 3. 3 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR3 Reasons to Care
  • 4. 4 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 1. Reduce Costs Fines up to 4% of Global Revenue *2016 Annual Revenues
  • 5. 5 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 2. Increase Margins GDPR Capabilities support digital transformation goals and drive new business models: • Consumer Centric PLM • Supply Chain & Channel Optimization • Customer 360 programs
  • 6. 6 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 3. Grow Revenue Data Monetization & New Revenue Streams • Sports “Wearables” • Self Identification at POI • Cloud Based Services “Trust” with Partners & Customers
  • 7. 7 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC The Clock is Ticking…
  • 8. 8 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Defining GDPR GDPR is a comprehensive set of privacy regulations designed to protect data for individuals within the European Union. Objective: • Give individuals control of their personal data • Regulatory consistency across the EU Impact: • Covers personal data collected in EU regardless of where the data collector is located • All US based multi nationals doing business with people in Europe will be impacted
  • 9. 9 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR’s Impact on Companies Any business (foreign or domestic) engaged with individuals within the EU The notion of Personal Information (PI) is broadly defined: data that has the potential to identify a person living in Europe falls under the GDPR GDPR applies “horizontally” across the organization’s business components, and “vertically” at all decision making levels. GDPR applies across the complete value chain. Organizations are obligated to verify the compliance of parties with which they do business.
  • 10. 10 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR Requires Interpretation General Data Protection Regulation
  • 11. 11 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR Requires Interpretation It’s Comprehensive & Tightly Written • All personal information regardless of where it came from and how it is used is governed It’s Principle Based • Requires companies to adopt privacy principles at the cultural level It’s Compromise Legislation • GDPR is a piece of what legal scholars call compromise legislation: a legislative text that tries to satisfy two starkly opposed sides of the data protection debate When Interpretation is Required, Best Practices are Critical
  • 12. 12 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC The Governance Challenge Creating transparent & defensible best practices that address “principles”
  • 13. 13 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Risk Management Accountability Org Design Data Lineage Process Alignment PII Cataloging International Partner Management Metadata Data Governance Data Architecture Data Operations Data Discovery Best Practices Security Data Management Privacy Cloud Services IoT The Governance Challenge Mapping the best practices to observable & measurable activities across many functional areas Processes Objectives Standards Metrics Data Rules
  • 14. 14 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC The 4 Core Capabilities GDPR requirements can be simplified by organizing around four core capability areas: Consultation & Reporting • Certification • Risk Management • Organizational Alignment • Privacy by Design • Risk Management • Communication • Remediation • People • Partners • Regulators • Organization
  • 15. 15 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC People: The “owners” of Personal Information Forget Quarantine Package Fix Consent Notification Access • Greater detail and clarity is called for when collecting data • Consent must be explicit as to use of data, how it will be processed, and by whom • Notification of breach is required (within 72 hours to the regulator) Under GDPR Individuals have the following rights: • To be Informed • To Access • To Rectify • To Erasure • To Restrict Processing • To Data Portability • To Object • Related to automated Decision Making and Profiling Obligations Rights
  • 16. 16 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Organization: “Data Protection by Design” Data Management International Best Practices Risk Management Accountability Obligations • Accountability – vertically, horizontally and externally • Data Protection Officer required for most large companies • Best practice “Codes of Conduct” mitigate against enforcement action • Assessment of risk will drive multiple decisions – it needs to be transparent and defensible • Cross border data exchanges do not obviate requirements
  • 17. 17 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Partners: A New Risk Dimension Certification Risk Management Processor Compliance Obligations • Transfers of Personal Information between your company and business partners does not transfer the responsibility to ensure it is safeguarded – it is still yours to look after • Establish a way to ensure your partners are providing GDPR level security • Best practices certifications that support third party audits will streamline assessment process and mitigate risk • Due diligence and transparency is key to demonstrating diligence
  • 18. 18 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Regulators: Communication is key Consultation Best Practices Obligations • Notification is required in the event of a breach • “Breach” is broadly defined: destruction, loss, alteration, unauthorized disclosure of, or access to, personal data • Reporting to regulators within 72 hours when breach is likely to result in a risk to the rights and freedoms of individuals • “Prior Consultation” is an expectation • Privacy Impact Assessment anchors the regulator and risk discussions • Best Practices will streamline these discussions
  • 19. 19 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR6 Steps to Readiness
  • 20. 20 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 1. Readiness Baseline Compliance Capability Readiness=+ Do the Right Thing – Do it Right! Understand Where You Are
  • 21. 21 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 2. Best Practices Aligning to Recognized Best Practice Frameworks Mitigates Risk 2 Talk the Talk – Walk the Walk 3 Promote within Industry Associations Pick a Framework That Works for You1 Understand How You Want to Manage
  • 22. 22 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC What is my GDPR Related Data?
  • 23. 23 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 3. Catalog “To understand yourself is the beginning of wisdom.” – Krishnamaurti 2 Catalog Data: Foundational to Managing Data 3 Describe Data: Tag to Answer Compliance Requirements Identify Data: PI; Sensitive; Packaged; Erasable1 Understand What You are Managing
  • 24. 24 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Who is in charge? Why is this information valuable? And what is the impact of a privacy breach? Why Do I Have It; How Is It Used?
  • 25. 25 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 4. Data Lifecycle Where Is It and How Is It Used? Lineage is a challenge! • E-commerce sites • Marketing functions • Shipping fulfillment • CRM Start with known Business Functions Focus on Core Requirements • Consent • Notification • Remediation • Partner Management
  • 26. 26 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 5. Build Risk Capabilities Defensible; Transparent; Demonstrable Vulnerabilities 17-2 32-1 32-2 33-1 33-3 34-1 GDPR Risk Areas 34-3 35-1 35-7-c,d 35-11 49-1-a Practices Mitigation RiskGovernance Risk Analysis & Metrics “To [the] rights and freedoms of natural persons”
  • 27. 27 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Am I Ready For the Regulators?
  • 28. 28 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 6. Governance Framework Operating Model Organizational Alignment Mobilizing Cross- Functional Teams Empowerment (with Rules and Tools) Outcome focused Metrics Ownership & Accountability Step-Change Change Management Pulling it all Together!
  • 29. 29 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPRQuestions? Jonathan Adams; 443-223-2534 jonathan.adams@datumstrategy.com
  • 30. 30 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Some Useful Links Whitepapers • GDPR Guide: 3 Steps to Readiness: http://info.datumstrategy.com/gdpr-guide-ebook-paper-privacy-compliance Blogs • Will the Privacy Shield Protect You? http://www.datumstrategy.com/blog/will-the-privacy-shield-protect-you • 7 Key GDPR Requirements & the Role of Data Governance: http://www.datumstrategy.com/blog/gdpr-requirements-and-data- governance • What’s GDPR and the Penalty for Not Complying? http://www.datumstrategy.com/blog/what-is-gdpr-fines-penalties-for-not- complying Websites • GDPR Portal: http://www.eugdpr.org • DATUM Strategy: http://www.datumstrategy.com Informative Sites: • The UK Information Commissioner’s Office (ICO) has a well put together site that makes it easy to find answers: https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/ • The Linklaters Law Firm has a number of resource papers (versus marketing papers): The General Data Protection Regulation: A Survival Guide; and A report on global data protection laws in 2016. https://clientsites.linklaters.com/Clients/dataprotected/Pages/TheGDPR.aspx • The book by Chiara Rustici: Applying the GDPR: Privacy Rules For The Data Economy is very informative. Pre-release is out http://shop.oreilly.com/product/0636920055723.do