SlideShare a Scribd company logo
1 of 58
Sophie’s Privacy
and the General Data Protection Regulation
A kick-start guide to prepare for May 2018 and beyond
By your name
Your role
Your name
your title
Contact data
Sophie & I
• Pre-war
• 1950 - European Declaration of Rights
• 1995 – Privacy directives
• In between – plenty of local laws and agreements
• May 2016 – General Data Protection Regulation
• Grace period
• May 2018 – law
history
Info, purpose,
context
Personal data
Sensitive data
Data Subject
Data Controller
Data Processor
Consent
Privacy by Design
Data Protection Officer
Data Protection Authority
Right to Access
Right to be forgotten
Retention
Vocabulary &
concepts
• Collect, input, order, store, modify, change, request, consult, use,
pass on, bring together, relate, protect, delete, destroy
• With or without human intervention
• SSO via twitter, google, FB
• Sync devices
• Workflows
• Automated processes
• Sub contractors
• …
Processing =
6 principles to
remember
1. Requiring transparency on the handling and
use of personal data.
2. Limiting personal data processing to
specified, legitimate purposes.
3. Limiting personal data collection and storage
to intended purposes.
4. Enabling individuals to correct or request
deletion of their personal data.
5. Limiting the storage of personally identifiable
data for only as long as necessary for its
intended purpose.
6. Ensuring personal data is protected using
appropriate security practices
Keep it safe and
controlled
Personal data :
1 what is the origin?
2 where is it stored?
3 how is it processed?
5. Where does it travel to?
6. Who has access?
HR dept Sales reps Marketing Accounting …
S
source
I
information
P
process
O
output
C
customer
Discover:
Identify what personal data you have and
where it resides
In-scope:
Any data that helps you
identify a person
• Name
• Email address
• Social media posts
• Physical,
physiological, or
genetic information
• Medical information
• Location
• Bank details
• IP address
• Cookies
• Cultural identity
Inventory:
Identifying where
personal data is
collected and stored
• Emails
• Documents
• Databases
• Removable media
• Metadata
• Log files
• Backups
Microsoft Azure
Microsoft Azure Data Catalog
Enterprise Mobility + Security (EMS)
Microsoft Cloud App Security
Dynamics 365
Audit Data & User Activity
Reporting & Analytics
Office & Office 365
Data Loss Prevention
Advanced Data Governance
Advanced Security Management
Office 365 eDiscovery
SQL Server and Azure SQL Database
SQL Query Language
Windows & Windows Server
Windows Search
Example solutions
Sophie applies for a job
in your company
• How much & what data?
• Selection tests
• Consent
• How long can I store CV’s?
• Right to be forgotten
• CAO’s on privacy (81,68,…)
• Contract amendments
You : Controller
Facebook : Processor
Facebook : Controller
Sophie’s new employer
work
Sub-
contractors
processes IT choices
GDPR impact on
Meet Marco, the IT guy
Large volumes of
personal data
Public
Health
Local IT – Business as usual
• Uncontrolled access
• No logs
• Complex (expensive) security
• No print policy
• …
GDPR
Boundary challenge (shadow IT)
Auditing & tracking obligations
BYOD
ACCOUNTABILITY
Retention policies
Data Protection
Centralizing in the cloud
US challenges
Safe Harbour
Privacy Shield
Contractual engagements
1 version of the truth
 GDPR compliant Cloud Partner*
 Microsoft Office 365
 Microsoft Azure
 Microsoft Dynamics 365
 Microsoft EM+S
Commitment by May 2018
Sophie at her desk
- ID management
- Sources
- Devices
- Data
Windows Hello
Defender
Device Guard
Credential Guard
Bitlocker
Office 365
Functional needs centralized
Marketing
• Security guards and cameras
• Biometric access controls
Physical data protections
Trust
Assume Breach
Identify Attacks
Restore Environment
R E D T E A M
Simulates
real-world attacks
B LU E T E A M
Detects, protects,
recovers
Office 365
Maximizing GDPR Compliancy
Sub-
contractors
Sophie in a meeting
- Shared data
- Devices
- People
Sophie on the road
- Connectivity
- Devices
- Prints
ID
Device
Data
87
13
I take docs I made
yes no
28
72
I take company data
yes no
88% strategy docs
31% customer data
25% IP
When I leave the company
47
84
37 32
0
20
40
60
80
100
Personal
mail
Ext HD Prints Dropbox
like
How ?
I take docs I made
Sophie at home
- Devices
- Access
- Prints
Role-based security
Record-based security
Field-level security
Data Loss Prevention
E-discovery
Advanced threat protection (behaviour bases)
Logs
Audits
Security Development Lifecycle
Encryption
Recomendations
GDPR
1. Why?
Align EU privacy laws
2. Who is concerned?
Organisations dealing with EU citizens data
3. Impact?
Be very vigilant
4. How can you be compliant?
Optimize your end-to-end personal data handling
5. What to do?
Visit www.thedataprotectionoffice.eu and closely collaborate with your IT partner
6. Where and when is it happening?
Everywhere in the world EU citizens data is handled, May 2018
yourname
function
contact data
Hans Demeyer
Supplier of Optimism & Inspiration
Linkedin/in/hansdemeyer
Twitter : suppl_of_optim
Facebook.com/mroptimism
www.thedataprotectionoffice.eu
About the author
GDPR for marketeers
Article in speaker notes
6 misverstanden over GDPR
Artikel in speaker notes

More Related Content

What's hot

Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection RegulationSabrina Kirrane
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR OverviewGydeline Ltd
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpJason Lackey
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashedChris Gilmour
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessOlivier BARROT
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)Huub de Jong
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for developmentTomppa Järvinen
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance Tom Haynes
 

What's hot (20)

Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
Simple GDPR Overview
Simple GDPR OverviewSimple GDPR Overview
Simple GDPR Overview
 
GDPR 11/1/2017
GDPR 11/1/2017GDPR 11/1/2017
GDPR 11/1/2017
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
GDPR practical info session for development
GDPR practical info session for developmentGDPR practical info session for development
GDPR practical info session for development
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
 

Similar to Sophie's Privacy - a story about GDPR

Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Ragnar Heil
 
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...Rencore
 
Digital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneDigital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneBrand Digital, Inc
 
How to implement gdpr in your document repository
How to implement gdpr in your document repository How to implement gdpr in your document repository
How to implement gdpr in your document repository XeniT Solutions nv
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityDrew Madelung
 
Data Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint WebinarData Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint WebinarConcept Searching, Inc
 
A very clear gdpr story for normal people
A very clear gdpr story for normal peopleA very clear gdpr story for normal people
A very clear gdpr story for normal peopleHans Demeyer
 
Tackling GDPR with Microsoft 365 and Office 365 - SpiceWorks
Tackling GDPR with Microsoft 365 and Office 365 - SpiceWorksTackling GDPR with Microsoft 365 and Office 365 - SpiceWorks
Tackling GDPR with Microsoft 365 and Office 365 - SpiceWorksIT Masterclasses
 
Top 10 use cases for Microsoft Purview.pptx
Top 10 use cases for Microsoft Purview.pptxTop 10 use cases for Microsoft Purview.pptx
Top 10 use cases for Microsoft Purview.pptxAlistair Pugin
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Andy Talbot
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxTimBee1
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxTimBee1
 
GDPR and Dynamics 365 - the Waldorf and Statler perspective
GDPR and Dynamics 365 - the Waldorf and Statler perspectiveGDPR and Dynamics 365 - the Waldorf and Statler perspective
GDPR and Dynamics 365 - the Waldorf and Statler perspectiveJoris Poelmans
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
Office 365 GDPR Presentation
Office 365 GDPR PresentationOffice 365 GDPR Presentation
Office 365 GDPR PresentationLuc Marolt
 
How Microsoft 365 can help with GDPR compliance
How Microsoft 365 can help with GDPR complianceHow Microsoft 365 can help with GDPR compliance
How Microsoft 365 can help with GDPR complianceIT Masterclasses
 
GDPR for Things - ThingsCon Amsterdam 2017
GDPR for Things - ThingsCon Amsterdam 2017GDPR for Things - ThingsCon Amsterdam 2017
GDPR for Things - ThingsCon Amsterdam 2017Saskia Videler
 
TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...
TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...
TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...Omo Osagiede
 
Digital Security and Data Protection Considerations for Hospitality Brands an...
Digital Security and Data Protection Considerations for Hospitality Brands an...Digital Security and Data Protection Considerations for Hospitality Brands an...
Digital Security and Data Protection Considerations for Hospitality Brands an...TBEX
 
One name unify them all
One name unify them allOne name unify them all
One name unify them allBizTalk360
 

Similar to Sophie's Privacy - a story about GDPR (20)

Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
Webinar Metalogix "Auf der Zielgeraden zur DSGVO!"
 
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
 
Digital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session OneDigital Marketing Analytics Certification - Session One
Digital Marketing Analytics Certification - Session One
 
How to implement gdpr in your document repository
How to implement gdpr in your document repository How to implement gdpr in your document repository
How to implement gdpr in your document repository
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & Sensitivity
 
Data Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint WebinarData Breaches and Security Rights in SharePoint Webinar
Data Breaches and Security Rights in SharePoint Webinar
 
A very clear gdpr story for normal people
A very clear gdpr story for normal peopleA very clear gdpr story for normal people
A very clear gdpr story for normal people
 
Tackling GDPR with Microsoft 365 and Office 365 - SpiceWorks
Tackling GDPR with Microsoft 365 and Office 365 - SpiceWorksTackling GDPR with Microsoft 365 and Office 365 - SpiceWorks
Tackling GDPR with Microsoft 365 and Office 365 - SpiceWorks
 
Top 10 use cases for Microsoft Purview.pptx
Top 10 use cases for Microsoft Purview.pptxTop 10 use cases for Microsoft Purview.pptx
Top 10 use cases for Microsoft Purview.pptx
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
GDPR and Dynamics 365 - the Waldorf and Statler perspective
GDPR and Dynamics 365 - the Waldorf and Statler perspectiveGDPR and Dynamics 365 - the Waldorf and Statler perspective
GDPR and Dynamics 365 - the Waldorf and Statler perspective
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Office 365 GDPR Presentation
Office 365 GDPR PresentationOffice 365 GDPR Presentation
Office 365 GDPR Presentation
 
How Microsoft 365 can help with GDPR compliance
How Microsoft 365 can help with GDPR complianceHow Microsoft 365 can help with GDPR compliance
How Microsoft 365 can help with GDPR compliance
 
GDPR for Things - ThingsCon Amsterdam 2017
GDPR for Things - ThingsCon Amsterdam 2017GDPR for Things - ThingsCon Amsterdam 2017
GDPR for Things - ThingsCon Amsterdam 2017
 
TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...
TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...
TBEX 2018 - Digital Security and GDPR Considerations for the Travel and Hospi...
 
Digital Security and Data Protection Considerations for Hospitality Brands an...
Digital Security and Data Protection Considerations for Hospitality Brands an...Digital Security and Data Protection Considerations for Hospitality Brands an...
Digital Security and Data Protection Considerations for Hospitality Brands an...
 
One name unify them all
One name unify them allOne name unify them all
One name unify them all
 

More from Hans Demeyer

Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Hans Demeyer
 
Discovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainDiscovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainHans Demeyer
 
De verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinDe verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinHans Demeyer
 
Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Hans Demeyer
 
Je brein houdt je voor de gek
Je brein houdt je voor de gekJe brein houdt je voor de gek
Je brein houdt je voor de gekHans Demeyer
 
Infographic - gdpr and smb
Infographic -  gdpr and smbInfographic -  gdpr and smb
Infographic - gdpr and smbHans Demeyer
 
Speed dating with GDPR
Speed dating with GDPRSpeed dating with GDPR
Speed dating with GDPRHans Demeyer
 
Communicate effectively
Communicate effectivelyCommunicate effectively
Communicate effectivelyHans Demeyer
 
Sustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologySustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologyHans Demeyer
 
Conversation styling
Conversation stylingConversation styling
Conversation stylingHans Demeyer
 
Conversation styling
Conversation stylingConversation styling
Conversation stylingHans Demeyer
 
Stuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProStuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProHans Demeyer
 
Vox entrepreneurs_nl
Vox entrepreneurs_nlVox entrepreneurs_nl
Vox entrepreneurs_nlHans Demeyer
 
Meer verkopen, minder babbelen
Meer verkopen, minder babbelenMeer verkopen, minder babbelen
Meer verkopen, minder babbelenHans Demeyer
 
From Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessFrom Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessHans Demeyer
 
Sales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourSales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourHans Demeyer
 
Sales training (focus on telesales)
Sales training (focus on telesales)Sales training (focus on telesales)
Sales training (focus on telesales)Hans Demeyer
 
Public speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audiencePublic speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audienceHans Demeyer
 

More from Hans Demeyer (20)

Shiny goals keynote (1hr)
Shiny goals keynote (1hr)Shiny goals keynote (1hr)
Shiny goals keynote (1hr)
 
Discovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brainDiscovering hidden treasures of your pirate brain
Discovering hidden treasures of your pirate brain
 
De verborgen schat van het piratenbrein
De verborgen schat van het piratenbreinDe verborgen schat van het piratenbrein
De verborgen schat van het piratenbrein
 
Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?Je brein houdt je goed voor de gek, laat jij je vangen?
Je brein houdt je goed voor de gek, laat jij je vangen?
 
Je brein houdt je voor de gek
Je brein houdt je voor de gekJe brein houdt je voor de gek
Je brein houdt je voor de gek
 
Infographic - gdpr and smb
Infographic -  gdpr and smbInfographic -  gdpr and smb
Infographic - gdpr and smb
 
Speed dating with GDPR
Speed dating with GDPRSpeed dating with GDPR
Speed dating with GDPR
 
Communicate effectively
Communicate effectivelyCommunicate effectively
Communicate effectively
 
Sustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable TechnologySustainable Entrepreneurship with Sustainable Technology
Sustainable Entrepreneurship with Sustainable Technology
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
 
Conversation styling
Conversation stylingConversation styling
Conversation styling
 
Stuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales ProStuff we can learn from the Challenger Sales Pro
Stuff we can learn from the Challenger Sales Pro
 
Challenger sales
Challenger salesChallenger sales
Challenger sales
 
Happiness
HappinessHappiness
Happiness
 
Vox entrepreneurs_nl
Vox entrepreneurs_nlVox entrepreneurs_nl
Vox entrepreneurs_nl
 
Meer verkopen, minder babbelen
Meer verkopen, minder babbelenMeer verkopen, minder babbelen
Meer verkopen, minder babbelen
 
From Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying ProcessFrom Sales Person to Facilitator of a Buying Process
From Sales Person to Facilitator of a Buying Process
 
Sales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch TourSales Pitch at TechData Touch Tour
Sales Pitch at TechData Touch Tour
 
Sales training (focus on telesales)
Sales training (focus on telesales)Sales training (focus on telesales)
Sales training (focus on telesales)
 
Public speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audiencePublic speaking : prepare for great sex with your audience
Public speaking : prepare for great sex with your audience
 

Recently uploaded

Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesKeppelCorporation
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menzaictsugar
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCRashishs7044
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Investment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy CheruiyotInvestment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy Cheruiyotictsugar
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Kirill Klimov
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchirictsugar
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMintel Group
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedKaiNexus
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Future Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionFuture Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionMintel Group
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxMarkAnthonyAurellano
 

Recently uploaded (20)

Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Annual General Meeting Presentation Slides
Annual General Meeting Presentation SlidesAnnual General Meeting Presentation Slides
Annual General Meeting Presentation Slides
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu MenzaYouth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
Youth Involvement in an Innovative Coconut Value Chain by Mwalimu Menza
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Investment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy CheruiyotInvestment in The Coconut Industry by Nancy Cheruiyot
Investment in The Coconut Industry by Nancy Cheruiyot
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchir
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 Edition
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Future Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted VersionFuture Of Sample Report 2024 | Redacted Version
Future Of Sample Report 2024 | Redacted Version
 
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptxContemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
Contemporary Economic Issues Facing the Filipino Entrepreneur (1).pptx
 

Sophie's Privacy - a story about GDPR

  • 1. Sophie’s Privacy and the General Data Protection Regulation A kick-start guide to prepare for May 2018 and beyond By your name Your role
  • 3. • Pre-war • 1950 - European Declaration of Rights • 1995 – Privacy directives • In between – plenty of local laws and agreements • May 2016 – General Data Protection Regulation • Grace period • May 2018 – law history
  • 5.
  • 6.
  • 7. Personal data Sensitive data Data Subject Data Controller Data Processor Consent Privacy by Design Data Protection Officer Data Protection Authority Right to Access Right to be forgotten Retention Vocabulary & concepts
  • 8. • Collect, input, order, store, modify, change, request, consult, use, pass on, bring together, relate, protect, delete, destroy • With or without human intervention • SSO via twitter, google, FB • Sync devices • Workflows • Automated processes • Sub contractors • … Processing =
  • 9. 6 principles to remember 1. Requiring transparency on the handling and use of personal data. 2. Limiting personal data processing to specified, legitimate purposes. 3. Limiting personal data collection and storage to intended purposes. 4. Enabling individuals to correct or request deletion of their personal data. 5. Limiting the storage of personally identifiable data for only as long as necessary for its intended purpose. 6. Ensuring personal data is protected using appropriate security practices
  • 10. Keep it safe and controlled Personal data : 1 what is the origin? 2 where is it stored? 3 how is it processed? 5. Where does it travel to? 6. Who has access?
  • 11. HR dept Sales reps Marketing Accounting … S source I information P process O output C customer
  • 12. Discover: Identify what personal data you have and where it resides In-scope: Any data that helps you identify a person • Name • Email address • Social media posts • Physical, physiological, or genetic information • Medical information • Location • Bank details • IP address • Cookies • Cultural identity Inventory: Identifying where personal data is collected and stored • Emails • Documents • Databases • Removable media • Metadata • Log files • Backups Microsoft Azure Microsoft Azure Data Catalog Enterprise Mobility + Security (EMS) Microsoft Cloud App Security Dynamics 365 Audit Data & User Activity Reporting & Analytics Office & Office 365 Data Loss Prevention Advanced Data Governance Advanced Security Management Office 365 eDiscovery SQL Server and Azure SQL Database SQL Query Language Windows & Windows Server Windows Search Example solutions
  • 13. Sophie applies for a job in your company • How much & what data? • Selection tests • Consent • How long can I store CV’s? • Right to be forgotten • CAO’s on privacy (81,68,…) • Contract amendments
  • 14. You : Controller Facebook : Processor Facebook : Controller
  • 15.
  • 17. Meet Marco, the IT guy
  • 18.
  • 19. Large volumes of personal data Public Health
  • 20. Local IT – Business as usual • Uncontrolled access • No logs • Complex (expensive) security • No print policy • …
  • 21.
  • 22.
  • 23.
  • 24. GDPR Boundary challenge (shadow IT) Auditing & tracking obligations BYOD ACCOUNTABILITY Retention policies Data Protection
  • 25. Centralizing in the cloud US challenges Safe Harbour Privacy Shield Contractual engagements
  • 26.
  • 27. 1 version of the truth  GDPR compliant Cloud Partner*  Microsoft Office 365  Microsoft Azure  Microsoft Dynamics 365  Microsoft EM+S Commitment by May 2018
  • 28.
  • 29.
  • 30.
  • 31. Sophie at her desk - ID management - Sources - Devices - Data
  • 32.
  • 35.
  • 37.
  • 38. • Security guards and cameras • Biometric access controls Physical data protections
  • 39. Trust Assume Breach Identify Attacks Restore Environment R E D T E A M Simulates real-world attacks B LU E T E A M Detects, protects, recovers
  • 42.
  • 43.
  • 44. Sophie in a meeting - Shared data - Devices - People
  • 45. Sophie on the road - Connectivity - Devices - Prints
  • 47. 87 13 I take docs I made yes no 28 72 I take company data yes no 88% strategy docs 31% customer data 25% IP When I leave the company 47 84 37 32 0 20 40 60 80 100 Personal mail Ext HD Prints Dropbox like How ? I take docs I made
  • 48. Sophie at home - Devices - Access - Prints
  • 49. Role-based security Record-based security Field-level security Data Loss Prevention E-discovery Advanced threat protection (behaviour bases) Logs Audits Security Development Lifecycle Encryption Recomendations
  • 50.
  • 51.
  • 52.
  • 53.
  • 54. GDPR 1. Why? Align EU privacy laws 2. Who is concerned? Organisations dealing with EU citizens data 3. Impact? Be very vigilant 4. How can you be compliant? Optimize your end-to-end personal data handling 5. What to do? Visit www.thedataprotectionoffice.eu and closely collaborate with your IT partner 6. Where and when is it happening? Everywhere in the world EU citizens data is handled, May 2018
  • 56. Hans Demeyer Supplier of Optimism & Inspiration Linkedin/in/hansdemeyer Twitter : suppl_of_optim Facebook.com/mroptimism www.thedataprotectionoffice.eu About the author
  • 57. GDPR for marketeers Article in speaker notes
  • 58. 6 misverstanden over GDPR Artikel in speaker notes