SlideShare a Scribd company logo
What is GDPR and why does it
matter to me?
stephanwgarcia@gmail.com
@sgarcia421
​Stephan Garcia
CRM Manager, Digital Catapult
So what is the GDPR…
​The General Data Protection Regulation
25th
May, 2018
The GDPR is characterised as wide-sweeping data reform
that brings power back into the hand of the individual.
• Awareness
• Consent
• Control
• Responsibility
​…and why does it matter?
Data Protection
​Data Protection Through the Years
1984 – Data Protection Act
1987 – Access to Personal Files Act
1995 – EU Data Protection Directive
1998 – Data Protection Act (DPA)
2001 – Windows XP
2003 – Privacy and Electronic Communications Regulations (EC Directive)
2008 - iPhone
​A Brief History
(1997)
The BIG Difference
​B2B vs B2C
Historically, it has come down to interpretation as the enforcement in the B2B world has always been lacking.
​Personal Data
Personal data means data which relate to a living individual who can be
identified –
(a) from those data, or
(b) from those data and other information which is in the possession of, or is
likely to come into the possession of, the data controller,
and includes any expression of opinion about the individual and any indication
of the intentions of the data controller or any other person in respect of the
individual.
Source: ico.co.uk
The Problem
​CRM is DRIVEN by Personal Data
How do you fight the theory that “If it doesn't exist within salesforce, it doesn't exist”
​Customer Relationship Management
As Salesforce Professionals, we must start
changing the way that we think about data.
The Problem
​“Personal data shall be adequate, relevant and not excessive in
relation to the purpose or purposes for which they are processed.”
​Customer Relationship Management
Awareness
​There are two things every website has in common, a Privacy Policy and Terms & Conditions
It is imperative that your data processing is outlined in both of these! Salesforce is not exempt from this!
​Make sure that your customers know how and why you are using their data!
When asked why you’re collecting any piece of information, you need must be able to provide a reasonable
explication.
What can I do?
• Gather your stakeholders together and review your Privacy Policy & Terms & Conditions
• Create a “Data Story” that enables you to explain the way that data travels through your organisation
• BONUS TIP! Make sure that that this story has an ending!
​Transparency is Key!
Awareness
​Transparency is Key!
More Info: http://bit.ly/DigicatPDR
​POC: Personal Data Receipts
Treating personal data submissions as transactions
• Increased visibility of data practice
• Multi layered opt-in
• Accessibility
Consent
​Pre-ticked checkboxes are a thing of the past
This is defined in the regulation, you must have explicit consent from the individual
​Recording of Consent
You must keep a thorough record of when/when consent was obtained
What can I do?
• Get rid of any pre-ticked checkboxes!!!
• Make sure you store the source of the opt-in and date on every level of opt-in.
• Review your data and make sure that you have a general idea of the source of opt-in as you aren’t required
re-request this information as long as you are comfortable that it was not obtained illegally.
​“Explicit Consent”
Control
​The Right to Be Forgotten
​The broad principle underpinning this right is to enable an individual to request
the deletion or removal of personal data whether there is no compelling reason
for its continued processing.
​The Right to Be Forgotten
Control
​The Right to be Forgotten
Any Individual has the right to have their data erased, without undue delay. This applies when the use of the
data is complete(eg. ending of service agreement) or when was collected or processed unlawfully.
​Subject Access Requests
Similar to the Freedom of Information Act, this requires you to promptly disclose any information you have on
an individual. This must be via electronic communication and completed within 30 days. This has existed in
the past, but was at a cost.
What can I do?
• Make sure you know where all personal data sits within Salesforce as well as discuss with your team where
other data might sit around the business.
• Create a checklist that enables you to track the deletion of data
• Create an easy way for your customers to request their data and/or erasure
​The Right to Be Forgotten
Responsibility
​The Data Processor, eg. Salesforce, is equally responsible as the Controller(you)
The processor must provide guidance and education to their users to make sure that best practice is being
followed.
​Protection Impact Assessments
The ICO has a right to request proof that an PIA has been completed
​Protection Impact Assessments
Infringement of the following GDPR provisions are subject to administrative fines up to €20,000,000 or in the
case of undertakings, up to 4% of global turnover, whichever is higher.
​“But Salesforce made me do it!!!”
Resources
​The ICO – 12 Steps to Prepare Yourself for the GDPR
http://bit.ly/ico12steps
​ICO – Guidance for Consent (more to come)
http://bit.ly/icoConsent
​ICO - GDPR Overview
http://bit.ly/icoGDPRoverview
​Trust the ICO
Thank Y u

More Related Content

What's hot

Seal datasheets | Seal Presentations
Seal datasheets | Seal PresentationsSeal datasheets | Seal Presentations
Seal datasheets | Seal Presentations
sealsoftwaredept
 
General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018
Fraser Hay
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
RominaMariaBaltariu
 
BigID Data sheet: Consent Governance & Orchestration
BigID Data sheet: Consent Governance & OrchestrationBigID Data sheet: Consent Governance & Orchestration
BigID Data sheet: Consent Governance & Orchestration
BigID Inc
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPR
GDPR Course
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
Sudarsan Reddy
 
Think Like Your Customer
Think Like Your CustomerThink Like Your Customer
Think Like Your Customer
IBM Analytics
 
Think like your customer
Think like your customerThink like your customer
Think like your customer
Trisha Dutta
 
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data Discovery to...
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data  Discovery to...BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data  Discovery to...
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data Discovery to...
BigID Inc
 
BigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR ComplianceBigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR Compliance
BigID Inc
 
BigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data SheetBigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
Dimitri Sirota
 
BigID Virtual MDM Data Sheet
BigID Virtual MDM Data SheetBigID Virtual MDM Data Sheet
BigID Virtual MDM Data Sheet
Dimitri Sirota
 
Stressing about GDPR? Key Facts
Stressing about GDPR? Key FactsStressing about GDPR? Key Facts
Stressing about GDPR? Key Facts
BizSmart Select
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
Neha Patel
 
Finding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA ComplianceFinding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA Compliance
Precisely
 
BigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data SheetBigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data Sheet
Dimitri Sirota
 
How big data analytics plugs into salesforce
How big data analytics plugs into salesforceHow big data analytics plugs into salesforce
How big data analytics plugs into salesforce
HIC Global Solutions
 
GDPR infographic
GDPR infographicGDPR infographic
Healthcare Patient Experiences Matter
Healthcare Patient Experiences MatterHealthcare Patient Experiences Matter
Healthcare Patient Experiences Matter
Ping Identity
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
Srijan Technologies
 

What's hot (20)

Seal datasheets | Seal Presentations
Seal datasheets | Seal PresentationsSeal datasheets | Seal Presentations
Seal datasheets | Seal Presentations
 
General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018General data protection regulation gdpr audit 2018
General data protection regulation gdpr audit 2018
 
Understanding gdpr compliance gdpr analytics tools
Understanding gdpr compliance  gdpr analytics toolsUnderstanding gdpr compliance  gdpr analytics tools
Understanding gdpr compliance gdpr analytics tools
 
BigID Data sheet: Consent Governance & Orchestration
BigID Data sheet: Consent Governance & OrchestrationBigID Data sheet: Consent Governance & Orchestration
BigID Data sheet: Consent Governance & Orchestration
 
Employee Training is Key to GDPR Compliance: GDPR
Employee Training is Key to GDPR Compliance:  GDPREmployee Training is Key to GDPR Compliance:  GDPR
Employee Training is Key to GDPR Compliance: GDPR
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Think Like Your Customer
Think Like Your CustomerThink Like Your Customer
Think Like Your Customer
 
Think like your customer
Think like your customerThink like your customer
Think like your customer
 
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data Discovery to...
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data  Discovery to...BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data  Discovery to...
BigID & Collibra Joint Deck: Using BigID’s Privacy-centric Data Discovery to...
 
BigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR ComplianceBigID Data Sheet: GDPR Compliance
BigID Data Sheet: GDPR Compliance
 
BigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data SheetBigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
BigID Data Subject Rights Automation for GDPR & Privacy Data Sheet
 
BigID Virtual MDM Data Sheet
BigID Virtual MDM Data SheetBigID Virtual MDM Data Sheet
BigID Virtual MDM Data Sheet
 
Stressing about GDPR? Key Facts
Stressing about GDPR? Key FactsStressing about GDPR? Key Facts
Stressing about GDPR? Key Facts
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
Finding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA ComplianceFinding Data at Risk for CCPA Compliance
Finding Data at Risk for CCPA Compliance
 
BigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data SheetBigID GDPR Privacy Automation Data Sheet
BigID GDPR Privacy Automation Data Sheet
 
How big data analytics plugs into salesforce
How big data analytics plugs into salesforceHow big data analytics plugs into salesforce
How big data analytics plugs into salesforce
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Healthcare Patient Experiences Matter
Healthcare Patient Experiences MatterHealthcare Patient Experiences Matter
Healthcare Patient Experiences Matter
 
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
 

Viewers also liked

Nessy Learnings Salesforce Marketing Automation Case Study
Nessy Learnings Salesforce Marketing Automation Case StudyNessy Learnings Salesforce Marketing Automation Case Study
Nessy Learnings Salesforce Marketing Automation Case Study
Desynit
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
IT Governance Ltd
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 
GDPR and its impact on digital communications | Digital trends seminar | 23 M...
GDPR and its impact on digital communications | Digital trends seminar | 23 M...GDPR and its impact on digital communications | Digital trends seminar | 23 M...
GDPR and its impact on digital communications | Digital trends seminar | 23 M...
CharityComms
 
Efficient Frontier What\'s Around The Corner Search Trends2
Efficient Frontier What\'s Around The Corner Search Trends2Efficient Frontier What\'s Around The Corner Search Trends2
Efficient Frontier What\'s Around The Corner Search Trends2
MerindaPeppard
 
How Social Media is Transforming Higher Education_ UCAS workshop 2014
How Social Media is Transforming Higher Education_ UCAS workshop 2014How Social Media is Transforming Higher Education_ UCAS workshop 2014
How Social Media is Transforming Higher Education_ UCAS workshop 2014
MerindaPeppard
 
Customer data and the new EU privacy law - May2016
Customer data and the new EU privacy law - May2016Customer data and the new EU privacy law - May2016
Customer data and the new EU privacy law - May2016
Andrew Sanderson
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
Lumension
 
EU Data Protection, Legislation and Certification
EU Data Protection, Legislation and Certification EU Data Protection, Legislation and Certification
EU Data Protection, Legislation and Certification
CRISP Project
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
Erica Walker
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
IISPEastMids
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
IT Governance Ltd
 
Ey segregation of_duties
Ey segregation of_dutiesEy segregation of_duties
Ey segregation of_duties
Indrani Bhattacharya
 
Sox Compliance Presentation
Sox Compliance PresentationSox Compliance Presentation
Sox Compliance Presentation
Skye Rogers
 
Command Query Responsibility Segregation
Command Query Responsibility SegregationCommand Query Responsibility Segregation
Command Query Responsibility Segregation
Skills Matter
 
eTOM - Foundation
eTOM - FoundationeTOM - Foundation
S O X In Telecom Industry
S O X In  Telecom  IndustryS O X In  Telecom  Industry
S O X In Telecom Industry
ravindra sharma
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud Providers
IT Governance Ltd
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
IT Governance Ltd
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
Iryna Chekanava
 

Viewers also liked (20)

Nessy Learnings Salesforce Marketing Automation Case Study
Nessy Learnings Salesforce Marketing Automation Case StudyNessy Learnings Salesforce Marketing Automation Case Study
Nessy Learnings Salesforce Marketing Automation Case Study
 
Preparing for EU GDPR
Preparing for EU GDPRPreparing for EU GDPR
Preparing for EU GDPR
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
GDPR and its impact on digital communications | Digital trends seminar | 23 M...
GDPR and its impact on digital communications | Digital trends seminar | 23 M...GDPR and its impact on digital communications | Digital trends seminar | 23 M...
GDPR and its impact on digital communications | Digital trends seminar | 23 M...
 
Efficient Frontier What\'s Around The Corner Search Trends2
Efficient Frontier What\'s Around The Corner Search Trends2Efficient Frontier What\'s Around The Corner Search Trends2
Efficient Frontier What\'s Around The Corner Search Trends2
 
How Social Media is Transforming Higher Education_ UCAS workshop 2014
How Social Media is Transforming Higher Education_ UCAS workshop 2014How Social Media is Transforming Higher Education_ UCAS workshop 2014
How Social Media is Transforming Higher Education_ UCAS workshop 2014
 
Customer data and the new EU privacy law - May2016
Customer data and the new EU privacy law - May2016Customer data and the new EU privacy law - May2016
Customer data and the new EU privacy law - May2016
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
EU Data Protection, Legislation and Certification
EU Data Protection, Legislation and Certification EU Data Protection, Legislation and Certification
EU Data Protection, Legislation and Certification
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Ey segregation of_duties
Ey segregation of_dutiesEy segregation of_duties
Ey segregation of_duties
 
Sox Compliance Presentation
Sox Compliance PresentationSox Compliance Presentation
Sox Compliance Presentation
 
Command Query Responsibility Segregation
Command Query Responsibility SegregationCommand Query Responsibility Segregation
Command Query Responsibility Segregation
 
eTOM - Foundation
eTOM - FoundationeTOM - Foundation
eTOM - Foundation
 
S O X In Telecom Industry
S O X In  Telecom  IndustryS O X In  Telecom  Industry
S O X In Telecom Industry
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud Providers
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
CyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPRCyNation: 7 Things You Should Know about EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
 

Similar to What is GDPR and why does it matter to me?

GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
Tech Trust
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
Ogilvy Consulting
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Financial Poise
 
GDPR Seminar Slides
GDPR Seminar SlidesGDPR Seminar Slides
GDPR Seminar Slides
Hannah Donnison
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
Financial Poise
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
Deeson
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
EMMAIntl
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
SilverTech
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
InfoGoTo
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
ObservePoint
 
California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)
Happiest Minds Technologies
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
Webkul Software Pvt. Ltd.
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
Naomi Holmes
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
Cobweb
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
Nate Stockard
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
Human Capital Department
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Richard Veryard
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
Spotler
 

Similar to What is GDPR and why does it matter to me? (20)

GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR Seminar Slides
GDPR Seminar SlidesGDPR Seminar Slides
GDPR Seminar Slides
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
GDPR webinar for business leaders
GDPR webinar for business leadersGDPR webinar for business leaders
GDPR webinar for business leaders
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)California Consumer Privacy Act (CCPA)
California Consumer Privacy Act (CCPA)
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
 

More from Desynit

Salesforce & GDPR: What happens next?
Salesforce & GDPR: What happens next? Salesforce & GDPR: What happens next?
Salesforce & GDPR: What happens next?
Desynit
 
How to create an inbound marketing engine
How to create an inbound marketing engineHow to create an inbound marketing engine
How to create an inbound marketing engine
Desynit
 
Are you ready for Lightning to strike?
Are you ready for Lightning to strike? Are you ready for Lightning to strike?
Are you ready for Lightning to strike?
Desynit
 
Dreamforce 2015 - 4 days in 4 minutes
Dreamforce 2015 - 4 days in 4 minutesDreamforce 2015 - 4 days in 4 minutes
Dreamforce 2015 - 4 days in 4 minutes
Desynit
 
Stories of sustainability on the Salesforce platform
Stories of sustainability on the Salesforce platform Stories of sustainability on the Salesforce platform
Stories of sustainability on the Salesforce platform
Desynit
 
Intro to Salesforce Lightning for Admins
Intro to Salesforce Lightning for Admins Intro to Salesforce Lightning for Admins
Intro to Salesforce Lightning for Admins
Desynit
 
Le Tour de Salesforce 2014
Le Tour de Salesforce 2014Le Tour de Salesforce 2014
Le Tour de Salesforce 2014
Desynit
 
Customer experience with IPC Media & Bluewolf
Customer experience with IPC Media & BluewolfCustomer experience with IPC Media & Bluewolf
Customer experience with IPC Media & Bluewolf
Desynit
 

More from Desynit (8)

Salesforce & GDPR: What happens next?
Salesforce & GDPR: What happens next? Salesforce & GDPR: What happens next?
Salesforce & GDPR: What happens next?
 
How to create an inbound marketing engine
How to create an inbound marketing engineHow to create an inbound marketing engine
How to create an inbound marketing engine
 
Are you ready for Lightning to strike?
Are you ready for Lightning to strike? Are you ready for Lightning to strike?
Are you ready for Lightning to strike?
 
Dreamforce 2015 - 4 days in 4 minutes
Dreamforce 2015 - 4 days in 4 minutesDreamforce 2015 - 4 days in 4 minutes
Dreamforce 2015 - 4 days in 4 minutes
 
Stories of sustainability on the Salesforce platform
Stories of sustainability on the Salesforce platform Stories of sustainability on the Salesforce platform
Stories of sustainability on the Salesforce platform
 
Intro to Salesforce Lightning for Admins
Intro to Salesforce Lightning for Admins Intro to Salesforce Lightning for Admins
Intro to Salesforce Lightning for Admins
 
Le Tour de Salesforce 2014
Le Tour de Salesforce 2014Le Tour de Salesforce 2014
Le Tour de Salesforce 2014
 
Customer experience with IPC Media & Bluewolf
Customer experience with IPC Media & BluewolfCustomer experience with IPC Media & Bluewolf
Customer experience with IPC Media & Bluewolf
 

Recently uploaded

20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
DianaGray10
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
DianaGray10
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
Kumud Singh
 
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
Neo4j
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
Edge AI and Vision Alliance
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
名前 です男
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
SOFTTECHHUB
 
20 Comprehensive Checklist of Designing and Developing a Website
20 Comprehensive Checklist of Designing and Developing a Website20 Comprehensive Checklist of Designing and Developing a Website
20 Comprehensive Checklist of Designing and Developing a Website
Pixlogix Infotech
 
Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...
Zilliz
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Albert Hoitingh
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
Aftab Hussain
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
KatiaHIMEUR1
 

Recently uploaded (20)

20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
 
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
GraphSummit Singapore | Enhancing Changi Airport Group's Passenger Experience...
 
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
“Building and Scaling AI Applications with the Nx AI Manager,” a Presentation...
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
 
20 Comprehensive Checklist of Designing and Developing a Website
20 Comprehensive Checklist of Designing and Developing a Website20 Comprehensive Checklist of Designing and Developing a Website
20 Comprehensive Checklist of Designing and Developing a Website
 
Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
 

What is GDPR and why does it matter to me?

  • 1. What is GDPR and why does it matter to me? stephanwgarcia@gmail.com @sgarcia421 ​Stephan Garcia CRM Manager, Digital Catapult
  • 2. So what is the GDPR… ​The General Data Protection Regulation 25th May, 2018 The GDPR is characterised as wide-sweeping data reform that brings power back into the hand of the individual. • Awareness • Consent • Control • Responsibility ​…and why does it matter?
  • 3. Data Protection ​Data Protection Through the Years 1984 – Data Protection Act 1987 – Access to Personal Files Act 1995 – EU Data Protection Directive 1998 – Data Protection Act (DPA) 2001 – Windows XP 2003 – Privacy and Electronic Communications Regulations (EC Directive) 2008 - iPhone ​A Brief History (1997)
  • 4. The BIG Difference ​B2B vs B2C Historically, it has come down to interpretation as the enforcement in the B2B world has always been lacking. ​Personal Data Personal data means data which relate to a living individual who can be identified – (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller, and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual. Source: ico.co.uk
  • 5. The Problem ​CRM is DRIVEN by Personal Data How do you fight the theory that “If it doesn't exist within salesforce, it doesn't exist” ​Customer Relationship Management As Salesforce Professionals, we must start changing the way that we think about data.
  • 6. The Problem ​“Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.” ​Customer Relationship Management
  • 7. Awareness ​There are two things every website has in common, a Privacy Policy and Terms & Conditions It is imperative that your data processing is outlined in both of these! Salesforce is not exempt from this! ​Make sure that your customers know how and why you are using their data! When asked why you’re collecting any piece of information, you need must be able to provide a reasonable explication. What can I do? • Gather your stakeholders together and review your Privacy Policy & Terms & Conditions • Create a “Data Story” that enables you to explain the way that data travels through your organisation • BONUS TIP! Make sure that that this story has an ending! ​Transparency is Key!
  • 8. Awareness ​Transparency is Key! More Info: http://bit.ly/DigicatPDR ​POC: Personal Data Receipts Treating personal data submissions as transactions • Increased visibility of data practice • Multi layered opt-in • Accessibility
  • 9. Consent ​Pre-ticked checkboxes are a thing of the past This is defined in the regulation, you must have explicit consent from the individual ​Recording of Consent You must keep a thorough record of when/when consent was obtained What can I do? • Get rid of any pre-ticked checkboxes!!! • Make sure you store the source of the opt-in and date on every level of opt-in. • Review your data and make sure that you have a general idea of the source of opt-in as you aren’t required re-request this information as long as you are comfortable that it was not obtained illegally. ​“Explicit Consent”
  • 10. Control ​The Right to Be Forgotten ​The broad principle underpinning this right is to enable an individual to request the deletion or removal of personal data whether there is no compelling reason for its continued processing. ​The Right to Be Forgotten
  • 11. Control ​The Right to be Forgotten Any Individual has the right to have their data erased, without undue delay. This applies when the use of the data is complete(eg. ending of service agreement) or when was collected or processed unlawfully. ​Subject Access Requests Similar to the Freedom of Information Act, this requires you to promptly disclose any information you have on an individual. This must be via electronic communication and completed within 30 days. This has existed in the past, but was at a cost. What can I do? • Make sure you know where all personal data sits within Salesforce as well as discuss with your team where other data might sit around the business. • Create a checklist that enables you to track the deletion of data • Create an easy way for your customers to request their data and/or erasure ​The Right to Be Forgotten
  • 12. Responsibility ​The Data Processor, eg. Salesforce, is equally responsible as the Controller(you) The processor must provide guidance and education to their users to make sure that best practice is being followed. ​Protection Impact Assessments The ICO has a right to request proof that an PIA has been completed ​Protection Impact Assessments Infringement of the following GDPR provisions are subject to administrative fines up to €20,000,000 or in the case of undertakings, up to 4% of global turnover, whichever is higher. ​“But Salesforce made me do it!!!”
  • 13. Resources ​The ICO – 12 Steps to Prepare Yourself for the GDPR http://bit.ly/ico12steps ​ICO – Guidance for Consent (more to come) http://bit.ly/icoConsent ​ICO - GDPR Overview http://bit.ly/icoGDPRoverview ​Trust the ICO