SlideShare una empresa de Scribd logo
1 de 25
Understanding the EU's new General
Data Protection Regulation (GDPR)
GDPR at Acquia
“Acquia is well positioned to meet the GDPR requirements by the May
2018 deadline. We are building on work we have done to obtain and
maintain our EU-U.S. Privacy Shield framework certification, as well as
our work with customers around the EU model clauses that Acquia
has also implemented.
We’re focused not only on meeting our own obligations, but also on
providing the tools that our customers will need to help them meet
their obligations under GDPR as well.”
Who am I
Tassos Koutlas, PhD
UK Technical Director, FFW
Have been working in technology for 15 years
- Drupal and the web
- Machine learning and machine vision
- Devops
Contents
● Context
● Definitions
● Principles
● Rights
● Penalties
● How to prepare
European law has two types of legislation:
1. Directives - Member states implement
2. Regulations - Immediately applicable
EU GDPR is a regulation.
1981 - EU Treaty 108 - 8 principles for protecting
personal data
1995 - EU Data Protection Directive (95/46/EC)
1998 - Human Rights Act (HRA 1998) - Art. 8 right
to privacy
2016 - EU GDPR approved, law in 2 years
Context
Definitions
Subject matter
Rules relating to the protection of natural persons
with regards to the processing of personal data.
Processing means any operation or
set of operations which is performed
on personal data.
Collection, recording, organisation, structuring,
storage, adaptation or alteration, retrieval,
consultation, use, disclosure by transmission,
dissemination or otherwise making available,
alignment or combination, restriction, erasure
or destruction.
Natural person is a living individual.
Personal data is any information relating to an
identified or identifiable natural person ('data
subject').
Name, identification number, location data, an
online identifier or any factor specific to the
physical, physiological, genetic, mental,
economic, cultural or social identity of that
natural person.
Controller
Determines the purposes and means of the
processing of personal data.
It can be a natural or legal person, public
authority, agency or other body which.
It can act alone or jointly with others.
FFW and Acquia are controllers on the data they
are collecting regarding their marketing
activities.
Processes personal data on behalf of the
controller.
It can be a natural or legal person, public
authority, agency or other body.
FFW and Acquia are processors for other parties
as part of their services.
Processor
Consent
It signifies agreement to the processing
of personal data.
It must be freely given and must give a
specific, informed and unambiguous
indication of the data subject's wishes.
It must be by a statement or by a clear
affirmative action.
Principles
Privacy by design
GDPR enforces the concept of data
protection by design and by default.
Businesses and organisations need to adhere
to a few principles with regards to the
personal data they are processing.
It is stated explicitly within the law that
organisations are responsible and should be
able to demonstrate compliance with those
principles.
Six principles
Six principles are mentioned with regards to personal data.
1. Should be processed lawfully,
fairly and in a transparent way.
2. Should be collected for
specified, explicit and legitimate
purpose.
3. Should be kept up to date.
4. Should be limited to what is
necessary.
5. Should not allow identification of
people for longer than necessary.
6. Should be processed in a way that
ensures appropriate security.
An example
Requiring consent to exhibit the lawfulness of
processing personal data (principle 1).
- Consent was freely given, specific, informed
and unambiguous.
- It was a positive opt-in
- The person was informed that she can
withdraw consent at any time.
Compliance:
- Clear privacy notice and terms and
conditions, opt-in rather than opt-out
- Ability for people to withdraw consent
Asking for feedback through a form via the
website capturing the email of a person.
Under GDPR an email is personal data.
Principle 6: Should be processed in a way that
ensures appropriate security.
Compliance:
- SSL and HTTPS traffic only through the
website
- Firewall policy for the database server
- Access controls for people accessing the
network
Another example
Rights
Rights
The following are mentioned with regards to
personal data.
Appropriate measures (processes, procedures
and training) to allow people to exercise those
rights.
All forms of communication would need to be
in a concise and easily accessible form using
clear and plain language.
Legal based documents would need to be
revised so they are more accessible by the
general public.
the right to be informed;
the right of access;
the right to rectification;
the right to erasure (right to be forgotten);
the right to restrict processing;
the right to data portability;
the right to object; and
the right not to be subject to automated
decision-making including profiling
An example
In May 2015 the EU Court of Justice ruled:
search engines are responsible to the content
they point to and thus they need to comply with
EU privacy law.
Google was asked to comply with the right to be
forgotten.
- Created the framework to remove search
results from EU index
- Created the process for people to request
removal
Establish processes, procedure and staff training
to deal with people exercising their rights.
Penalties
Low
Fine up to 10,000,000 EUR or 2% of total
worldwide turnover, whichever is higher.
- Child consent
- Processing not requiring identification
- Data protection by design and by default
- Joint controllers
- Representative of controllers not
established in EU
- Processing
- Cooperation with supervisory authority
- Data security
- Notifications of breaches to supervisory
authority
- Communication of breaches to data
subjects
Fine up to 20,000,000 EUR or 4% of total
worldwide turnover, whichever is higher.
- Principles relating to the processing of
personal data
- Lawfulness of processing
- Conditions of consent
- Processing of special categories of data
personal data (i.e. sensitive data)
- Data subjects rights
- Transfers to third countries
- Access to supervisory authority
- Order/limitations on processing or the
suspension of data flows
High
How to prepare
Steps to prepare
Awareness
Make sure that decision makers and
key people in your organisation are
aware that the law is changing to the
GDPR. They need to appreciate the
impact this is likely to have.
Privacy information
Review your current privacy
notices and put a plan in place to
make any necessary changes.
Information audit
Document what personal data you
hold, where it came from and who
you share it with.
Individual’s rights
Check procedures to ensure
they cover all the rights
individuals have (e.g. how to
delete personal data, or provide
data electronically in a common
used format)
Steps to prepare
Data breaches
Procedures to detect, report and
investigate a personal data breach
Data protection by design
and data protection impact
assessments
Familiarise with latest guidance
from Article 29 Working Group and
how to implement Privacy Impact
Assessments for your organisation
(or talk to us at FFW about it).
Access requests
Update procedures and plan how to
handle requests within the
timescales.
Lawful basis of processing
Identify your lawful basis of
processing, document it and update
privacy notice to explain it.
Children
Do you need to put systems in place
to verify individual’s ages and obtain
parental or guardian consent?
Steps to prepare
Data protection officers
Designate someone (within your
organisation or some legal entity) to
take responsibility for data
protection compliance. Asses where
the role will sit within the
organisational structure.
International
If your organisation operate in more
than one Member State determine
your lead data protection
supervisory authority
Organisations not
established in EU
Designate in writing a
representative in EU.
Case study - Hotjar
Thoroughly research the areas of our product and
our business impacted by GDPR - COMPLETE
Appoint a Data Protection Officer - COMPLETE
Rewrite our Data Protection Agreement -
COMPLETE
Develop a strategy and requirements for how to
address the areas of our product impacted by
GDPR - COMPLETE
Perform the necessary changes/improvements to
our product based on the requirements - IN
PROGRESS
Case study - Hotjar
Implement the required changes to our
internal processes and procedures required to
achieve and maintain compliance with GDPR
- IN PROGRESS
Thoroughly test all of our changes to verify
and validate compliance with GDPR - IN
PROGRESS (being done incrementally as
changes are completed)
Finalize and communicate our full
compliance - TO BE ANNOUNCED
Final Thoughts
To prepare for GDPR, you must understand which data you create, where
and how you process and finally store it.
Only then, you will be able to take the right actions to comply with the new
regulations. Acquia and FFW are ready to support you on this journey.
Questions

Más contenido relacionado

La actualidad más candente

GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
GDPR training
GDPR training GDPR training
GDPR training ASL
 
Any Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO StandardsAny Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO StandardsPECB
 
Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...Peter Procházka
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?PECB
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Kimberly Simon MBA
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacylegalPadmin
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfDaviesParker
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection ActSaimaRafiq
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701PECB
 

La actualidad más candente (20)

GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
GDPR training
GDPR training GDPR training
GDPR training
 
Any Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO StandardsAny Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO Standards
 
Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
All about a DPIA by Andrey Prozorov 2.0, 220518.pdf
All about a DPIA by Andrey Prozorov 2.0, 220518.pdfAll about a DPIA by Andrey Prozorov 2.0, 220518.pdf
All about a DPIA by Andrey Prozorov 2.0, 220518.pdf
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdf
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 

Similar a Understanding the EU's new General Data Protection Regulation (GDPR)

The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing MindsetNetworkIQ
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPRNeha Patel
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaperJim Wilson
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulationFahad Ameen
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteSilverTech
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationJoseph V. Moreno
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European unionRohana K Amarakoon
 
A quick look at gdpr
A quick look at gdprA quick look at gdpr
A quick look at gdprCookieYes
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 

Similar a Understanding the EU's new General Data Protection Regulation (GDPR) (20)

The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulation
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European union
 
A quick look at gdpr
A quick look at gdprA quick look at gdpr
A quick look at gdpr
 
GDPR
GDPRGDPR
GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 

Más de Acquia

Acquia_Adcetera Webinar_Marketing Automation.pdf
Acquia_Adcetera Webinar_Marketing Automation.pdfAcquia_Adcetera Webinar_Marketing Automation.pdf
Acquia_Adcetera Webinar_Marketing Automation.pdfAcquia
 
Acquia Webinar Deck - 9_13 .pdf
Acquia Webinar Deck - 9_13 .pdfAcquia Webinar Deck - 9_13 .pdf
Acquia Webinar Deck - 9_13 .pdfAcquia
 
Taking Your Multi-Site Management at Scale to the Next Level
Taking Your Multi-Site Management at Scale to the Next LevelTaking Your Multi-Site Management at Scale to the Next Level
Taking Your Multi-Site Management at Scale to the Next LevelAcquia
 
CDP for Retail Webinar with Appnovation - Q2 2022.pdf
CDP for Retail Webinar with Appnovation - Q2 2022.pdfCDP for Retail Webinar with Appnovation - Q2 2022.pdf
CDP for Retail Webinar with Appnovation - Q2 2022.pdfAcquia
 
May Partner Bootcamp 2022
May Partner Bootcamp 2022May Partner Bootcamp 2022
May Partner Bootcamp 2022Acquia
 
April Partner Bootcamp 2022
April Partner Bootcamp 2022April Partner Bootcamp 2022
April Partner Bootcamp 2022Acquia
 
How to Unify Brand Experience: A Hootsuite Story
How to Unify Brand Experience: A Hootsuite Story How to Unify Brand Experience: A Hootsuite Story
How to Unify Brand Experience: A Hootsuite Story Acquia
 
Using Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CX
Using Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CXUsing Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CX
Using Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CXAcquia
 
Improve Code Quality and Time to Market: 100% Cloud-Based Development Workflow
Improve Code Quality and Time to Market: 100% Cloud-Based Development WorkflowImprove Code Quality and Time to Market: 100% Cloud-Based Development Workflow
Improve Code Quality and Time to Market: 100% Cloud-Based Development WorkflowAcquia
 
September Partner Bootcamp
September Partner BootcampSeptember Partner Bootcamp
September Partner BootcampAcquia
 
August partner bootcamp
August partner bootcampAugust partner bootcamp
August partner bootcampAcquia
 
July 2021 Partner Bootcamp
July  2021 Partner BootcampJuly  2021 Partner Bootcamp
July 2021 Partner BootcampAcquia
 
May Partner Bootcamp
May Partner BootcampMay Partner Bootcamp
May Partner BootcampAcquia
 
DRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASY
DRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASYDRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASY
DRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASYAcquia
 
Work While You Sleep: The CMO’s Guide to a 24/7/365 Lead Machine
Work While You Sleep: The CMO’s Guide to a 24/7/365 Lead MachineWork While You Sleep: The CMO’s Guide to a 24/7/365 Lead Machine
Work While You Sleep: The CMO’s Guide to a 24/7/365 Lead MachineAcquia
 
Acquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B Leads
Acquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B LeadsAcquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B Leads
Acquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B LeadsAcquia
 
April partner bootcamp deck cookieless future
April partner bootcamp deck  cookieless futureApril partner bootcamp deck  cookieless future
April partner bootcamp deck cookieless futureAcquia
 
How to enhance cx through personalised, automated solutions
How to enhance cx through personalised, automated solutionsHow to enhance cx through personalised, automated solutions
How to enhance cx through personalised, automated solutionsAcquia
 
DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...
DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...
DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...Acquia
 
Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021
Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021
Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021Acquia
 

Más de Acquia (20)

Acquia_Adcetera Webinar_Marketing Automation.pdf
Acquia_Adcetera Webinar_Marketing Automation.pdfAcquia_Adcetera Webinar_Marketing Automation.pdf
Acquia_Adcetera Webinar_Marketing Automation.pdf
 
Acquia Webinar Deck - 9_13 .pdf
Acquia Webinar Deck - 9_13 .pdfAcquia Webinar Deck - 9_13 .pdf
Acquia Webinar Deck - 9_13 .pdf
 
Taking Your Multi-Site Management at Scale to the Next Level
Taking Your Multi-Site Management at Scale to the Next LevelTaking Your Multi-Site Management at Scale to the Next Level
Taking Your Multi-Site Management at Scale to the Next Level
 
CDP for Retail Webinar with Appnovation - Q2 2022.pdf
CDP for Retail Webinar with Appnovation - Q2 2022.pdfCDP for Retail Webinar with Appnovation - Q2 2022.pdf
CDP for Retail Webinar with Appnovation - Q2 2022.pdf
 
May Partner Bootcamp 2022
May Partner Bootcamp 2022May Partner Bootcamp 2022
May Partner Bootcamp 2022
 
April Partner Bootcamp 2022
April Partner Bootcamp 2022April Partner Bootcamp 2022
April Partner Bootcamp 2022
 
How to Unify Brand Experience: A Hootsuite Story
How to Unify Brand Experience: A Hootsuite Story How to Unify Brand Experience: A Hootsuite Story
How to Unify Brand Experience: A Hootsuite Story
 
Using Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CX
Using Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CXUsing Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CX
Using Personas to Guide DAM Results: How Life Time Pumped Up Their UX and CX
 
Improve Code Quality and Time to Market: 100% Cloud-Based Development Workflow
Improve Code Quality and Time to Market: 100% Cloud-Based Development WorkflowImprove Code Quality and Time to Market: 100% Cloud-Based Development Workflow
Improve Code Quality and Time to Market: 100% Cloud-Based Development Workflow
 
September Partner Bootcamp
September Partner BootcampSeptember Partner Bootcamp
September Partner Bootcamp
 
August partner bootcamp
August partner bootcampAugust partner bootcamp
August partner bootcamp
 
July 2021 Partner Bootcamp
July  2021 Partner BootcampJuly  2021 Partner Bootcamp
July 2021 Partner Bootcamp
 
May Partner Bootcamp
May Partner BootcampMay Partner Bootcamp
May Partner Bootcamp
 
DRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASY
DRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASYDRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASY
DRUPAL 7 END OF LIFE IS NEAR - MIGRATE TO DRUPAL 9 FAST AND EASY
 
Work While You Sleep: The CMO’s Guide to a 24/7/365 Lead Machine
Work While You Sleep: The CMO’s Guide to a 24/7/365 Lead MachineWork While You Sleep: The CMO’s Guide to a 24/7/365 Lead Machine
Work While You Sleep: The CMO’s Guide to a 24/7/365 Lead Machine
 
Acquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B Leads
Acquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B LeadsAcquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B Leads
Acquia webinar: Leveraging Drupal to Bury Your Sales Team In B2B Leads
 
April partner bootcamp deck cookieless future
April partner bootcamp deck  cookieless futureApril partner bootcamp deck  cookieless future
April partner bootcamp deck cookieless future
 
How to enhance cx through personalised, automated solutions
How to enhance cx through personalised, automated solutionsHow to enhance cx through personalised, automated solutions
How to enhance cx through personalised, automated solutions
 
DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...
DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...
DRUPAL MIGRATIONS AND DRUPAL 9 INNOVATION: HOW PAC-12 DELIVERED DIGITALLY FOR...
 
Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021
Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021
Customer Experience (CX): 3 Key Factors Shaping CX Redesign in 2021
 

Último

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 

Último (20)

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 

Understanding the EU's new General Data Protection Regulation (GDPR)

  • 1. Understanding the EU's new General Data Protection Regulation (GDPR)
  • 2. GDPR at Acquia “Acquia is well positioned to meet the GDPR requirements by the May 2018 deadline. We are building on work we have done to obtain and maintain our EU-U.S. Privacy Shield framework certification, as well as our work with customers around the EU model clauses that Acquia has also implemented. We’re focused not only on meeting our own obligations, but also on providing the tools that our customers will need to help them meet their obligations under GDPR as well.”
  • 3. Who am I Tassos Koutlas, PhD UK Technical Director, FFW Have been working in technology for 15 years - Drupal and the web - Machine learning and machine vision - Devops
  • 4. Contents ● Context ● Definitions ● Principles ● Rights ● Penalties ● How to prepare European law has two types of legislation: 1. Directives - Member states implement 2. Regulations - Immediately applicable EU GDPR is a regulation. 1981 - EU Treaty 108 - 8 principles for protecting personal data 1995 - EU Data Protection Directive (95/46/EC) 1998 - Human Rights Act (HRA 1998) - Art. 8 right to privacy 2016 - EU GDPR approved, law in 2 years Context
  • 6. Subject matter Rules relating to the protection of natural persons with regards to the processing of personal data. Processing means any operation or set of operations which is performed on personal data. Collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Natural person is a living individual. Personal data is any information relating to an identified or identifiable natural person ('data subject'). Name, identification number, location data, an online identifier or any factor specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • 7. Controller Determines the purposes and means of the processing of personal data. It can be a natural or legal person, public authority, agency or other body which. It can act alone or jointly with others. FFW and Acquia are controllers on the data they are collecting regarding their marketing activities. Processes personal data on behalf of the controller. It can be a natural or legal person, public authority, agency or other body. FFW and Acquia are processors for other parties as part of their services. Processor
  • 8. Consent It signifies agreement to the processing of personal data. It must be freely given and must give a specific, informed and unambiguous indication of the data subject's wishes. It must be by a statement or by a clear affirmative action.
  • 10. Privacy by design GDPR enforces the concept of data protection by design and by default. Businesses and organisations need to adhere to a few principles with regards to the personal data they are processing. It is stated explicitly within the law that organisations are responsible and should be able to demonstrate compliance with those principles.
  • 11. Six principles Six principles are mentioned with regards to personal data. 1. Should be processed lawfully, fairly and in a transparent way. 2. Should be collected for specified, explicit and legitimate purpose. 3. Should be kept up to date. 4. Should be limited to what is necessary. 5. Should not allow identification of people for longer than necessary. 6. Should be processed in a way that ensures appropriate security.
  • 12. An example Requiring consent to exhibit the lawfulness of processing personal data (principle 1). - Consent was freely given, specific, informed and unambiguous. - It was a positive opt-in - The person was informed that she can withdraw consent at any time. Compliance: - Clear privacy notice and terms and conditions, opt-in rather than opt-out - Ability for people to withdraw consent Asking for feedback through a form via the website capturing the email of a person. Under GDPR an email is personal data. Principle 6: Should be processed in a way that ensures appropriate security. Compliance: - SSL and HTTPS traffic only through the website - Firewall policy for the database server - Access controls for people accessing the network Another example
  • 14. Rights The following are mentioned with regards to personal data. Appropriate measures (processes, procedures and training) to allow people to exercise those rights. All forms of communication would need to be in a concise and easily accessible form using clear and plain language. Legal based documents would need to be revised so they are more accessible by the general public. the right to be informed; the right of access; the right to rectification; the right to erasure (right to be forgotten); the right to restrict processing; the right to data portability; the right to object; and the right not to be subject to automated decision-making including profiling
  • 15. An example In May 2015 the EU Court of Justice ruled: search engines are responsible to the content they point to and thus they need to comply with EU privacy law. Google was asked to comply with the right to be forgotten. - Created the framework to remove search results from EU index - Created the process for people to request removal Establish processes, procedure and staff training to deal with people exercising their rights.
  • 17. Low Fine up to 10,000,000 EUR or 2% of total worldwide turnover, whichever is higher. - Child consent - Processing not requiring identification - Data protection by design and by default - Joint controllers - Representative of controllers not established in EU - Processing - Cooperation with supervisory authority - Data security - Notifications of breaches to supervisory authority - Communication of breaches to data subjects Fine up to 20,000,000 EUR or 4% of total worldwide turnover, whichever is higher. - Principles relating to the processing of personal data - Lawfulness of processing - Conditions of consent - Processing of special categories of data personal data (i.e. sensitive data) - Data subjects rights - Transfers to third countries - Access to supervisory authority - Order/limitations on processing or the suspension of data flows High
  • 19. Steps to prepare Awareness Make sure that decision makers and key people in your organisation are aware that the law is changing to the GDPR. They need to appreciate the impact this is likely to have. Privacy information Review your current privacy notices and put a plan in place to make any necessary changes. Information audit Document what personal data you hold, where it came from and who you share it with. Individual’s rights Check procedures to ensure they cover all the rights individuals have (e.g. how to delete personal data, or provide data electronically in a common used format)
  • 20. Steps to prepare Data breaches Procedures to detect, report and investigate a personal data breach Data protection by design and data protection impact assessments Familiarise with latest guidance from Article 29 Working Group and how to implement Privacy Impact Assessments for your organisation (or talk to us at FFW about it). Access requests Update procedures and plan how to handle requests within the timescales. Lawful basis of processing Identify your lawful basis of processing, document it and update privacy notice to explain it. Children Do you need to put systems in place to verify individual’s ages and obtain parental or guardian consent?
  • 21. Steps to prepare Data protection officers Designate someone (within your organisation or some legal entity) to take responsibility for data protection compliance. Asses where the role will sit within the organisational structure. International If your organisation operate in more than one Member State determine your lead data protection supervisory authority Organisations not established in EU Designate in writing a representative in EU.
  • 22. Case study - Hotjar Thoroughly research the areas of our product and our business impacted by GDPR - COMPLETE Appoint a Data Protection Officer - COMPLETE Rewrite our Data Protection Agreement - COMPLETE Develop a strategy and requirements for how to address the areas of our product impacted by GDPR - COMPLETE Perform the necessary changes/improvements to our product based on the requirements - IN PROGRESS
  • 23. Case study - Hotjar Implement the required changes to our internal processes and procedures required to achieve and maintain compliance with GDPR - IN PROGRESS Thoroughly test all of our changes to verify and validate compliance with GDPR - IN PROGRESS (being done incrementally as changes are completed) Finalize and communicate our full compliance - TO BE ANNOUNCED
  • 24. Final Thoughts To prepare for GDPR, you must understand which data you create, where and how you process and finally store it. Only then, you will be able to take the right actions to comply with the new regulations. Acquia and FFW are ready to support you on this journey.

Notas del editor

  1. Under this scheme people would always have to opt-in with a request for consent form that presents information in a clear and distinguishable way. For example when a user registers for a service via their email, phone number, or social media profile they would need to explicitly check a check box. Long are the days of opting-out and clever wording on forms to get consent. People have a right to be informed and to be informed in clear language.
  2. Each request would need to be handled within a month from submission and free of charge, otherwise there are penalties imposed.
  3. Access Requests The data subject will have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed. Purpose of the processing Categories of personal data concerned To whom personal data has been disclosed Period that personal data will be stored Existence of the right to rectify or erase personal data