SlideShare una empresa de Scribd logo
1 de 11
General Data Protection 
Regulation, 2014 
Update document 
David Prince, CISSP, CISM 
Director – Information Security Consulting, Schillings 
@RiskObscurity 
InfoRisk.io
About me… 
①Information security evangelist 
②On-demand CISO/vCISO 
③Industry speaker and socialite 
①Director of Information Security Consulting @ Schillings 
②Blogger – InfoRisk.io/Schillings.co.uk 
③Give01Day Supporter! 
④ f
What is the General Data 
Protection Regulation? 
The purpose of the General Data Protection Regulation (“GDPR”) is to replace 
existing and incredibly outdated Data Protection legislation in-acted by various 
EU member-states with a single, unified regulation for protecting Personal Data. 
The Draft GDPR was introduced by the European Commission (“EC”) in January 
2012 with the latest version of the draft approved by the European Parliament in 
March 2014. 
Given the fundamental change in Data Protection at EU-level, there is still much 
negotiation to take place and it is suspected that the final form will not be 
approved until late next year, with a further 2-year enforcement deadline. 
However, with over 4,000 proposed amendments to the original legislation 
organizations should be reviewing their current Data Protection and Information 
Security posture now in preparation for this significant regulatory change. 
This slide-deck will outline just some of the most substantial changes organizations 
need to be aware of. 
① f
Increased fines 
Currently, under the Data Protection Act in the UK, the maximum penalty for 
non-compliance is £500,000, although the ICO (Information Commissioners 
Office), the UK Authority for the Data Protection Act, has only issued a maximum 
fine of £250,000. 
Many believe that these thresholds are far to low, given the devastation a loss of 
data can cause and its potential to cause even greater harm as we adopt 
Cloud computing and the Internet of Things (“IoT”) 
The new General Data Protection Regulation will come with fines of up to 5% of 
annual group-wide revenue, or €100 million, whichever sum is greatest. 
This is a substantial change that all organizations should take on board when 
allocating budget and priority to Data Protection and Information Security 
① f
Notification requirements 
According to the latest draft of the GDPR, organizations will be required to notify 
the National Supervisory Authority of all data breaches without undue delay 
within 72 hours, in addition to notifying the affected individuals of data-loss, 
similar to certain US federal law on Data Protection. E.g. the state of California. 
In instances were data has been encrypted and is unreadable (and therefore 
not compromised in terms of its Confidentiality and Integrity) it may not be 
necessary to notify. 
Currently, one of the biggest reasons for organizations being fine is due to lost or 
stolen devices that do not employ encryption. 
This requirement to notify means that organizations can no longer brush data-loss 
incidents under the rug and increases the likelihood of significant reputation 
and financial harm in the event of data loss.
Data Privacy Impact 
Assessments (DPIA) 
Both Data Controllers and Data Processors will be required to perform Data 
Privacy Impact Assessments (DPIAs) to identify how data handling procedures 
and processes (including what Personal Data is used for) could impact the 
safety of information associated to data-subjects, and overall compliance of 
that information under the GDPR 
This change will put in place greater administrative overhead to ensure 
compliance. Additionally, this change enforces Data Processors to become 
more responsible in ensuring Data Protection by mandating their compliance 
with the GDPR. 
This change aims to minimize Data Protection risk in the supply chain, which is 
often a cause of vulnerability that results in data-losses, which the Data 
Controller is accountable for.
Mandatory appointment of 
Data Protection Officer (DPO) 
Organizations that process the personal information of 5,000 individuals or more 
annually, or maintain data processing as a core business function will be 
required to hire a Data Protection Officer (DPO) to oversee data processing 
operations. 
Importantly, to ensure severance from business politics and conflicts of interest, 
this individual will be given enhanced employment rights, including a minimum 
tenure of 4 years, full time and 2 years for a contractor. 
Organizations may hire a single DPO for the entire business. However, they must, 
in all cases, have knowledge and experience in Data Protection law. 
Public authorities will be required to appoint a DPO regardless of the number of 
individuals’ personal data they process.
Application to non-EU 
organizations 
Organizations that are not based within the EU, but target EU citizens with goods 
and services will be required to comply with the GDPR.
Application to Data Processors 
In the current Data Protection Act, Data Controllers are entirely accountable for 
the protection of Personal Data, even if some of that data is processed by third-party 
organizations acting as Data Processors. 
Under the GDPR Data Processors will be required to comply with the GDPR 
which means they share the liability of data-loss incidents and non-compliance.
Application to Data Processors 
In the current Data Protection Act, Data Controllers are entirely accountable for 
the protection of Personal Data, even if some of that data is processed by third-party 
organizations acting as Data Processors. 
Under the GDPR Data Processors will be required to comply with the GDPR 
which means they share the liability of data-loss incidents and non-compliance.
Thank you. 
Other changes to be aware of: 
1. Right to be forgotten. 
Click here to see Select Committee report in July 2014. 
1. Explicit Consent. 
Individuals are required to give consent for their data 
to be processed. 
David Prince, CISSP, CISM 
Director – Information Security Consulting, Schillings 
@RiskObscurity 
InfoRisk.io

Más contenido relacionado

Último

Navigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptxNavigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptxelysemiller87
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理bd2c5966a56d
 
Career As Legal Reporters for Law Students
Career As Legal Reporters for Law StudentsCareer As Legal Reporters for Law Students
Career As Legal Reporters for Law StudentsNilendra Kumar
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxIshikaChauhan30
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理Airst S
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee
 
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理e9733fc35af6
 
买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量
买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量
买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量acyefsa
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理Airst S
 
一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理Fir La
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理Airst S
 
一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理ss
 
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理bd2c5966a56d
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理Airst S
 
Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Abdul-Hakim Shabazz
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理Airst S
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSCssSpamx
 
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理e9733fc35af6
 

Último (20)

Navigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptxNavigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptx
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
Career As Legal Reporters for Law Students
Career As Legal Reporters for Law StudentsCareer As Legal Reporters for Law Students
Career As Legal Reporters for Law Students
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptx
 
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
一比一原版(JCU毕业证书)詹姆斯库克大学毕业证如何办理
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
 
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
 
买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量
买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量
买(rice毕业证书)莱斯大学毕业证本科文凭证书原版质量
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
 
一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理
 
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
一比一原版(ECU毕业证书)埃迪斯科文大学毕业证如何办理
 
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy NovicesIt’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
It’s Not Easy Being Green: Ethical Pitfalls for Bankruptcy Novices
 
一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)昆特兰理工大学毕业证如何办理
 
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
一比一原版(Griffith毕业证书)格里菲斯大学毕业证如何办理
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理
 
Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?
 
Chambers Global Practice Guide - Canada M&A
Chambers Global Practice Guide - Canada M&AChambers Global Practice Guide - Canada M&A
Chambers Global Practice Guide - Canada M&A
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSSASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
ASMA JILANI EXPLAINED CASE PLD 1972 FOR CSS
 
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
 

Destacado

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

Destacado (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

General Data Protection Regulation - 2014 Updates

  • 1. General Data Protection Regulation, 2014 Update document David Prince, CISSP, CISM Director – Information Security Consulting, Schillings @RiskObscurity InfoRisk.io
  • 2. About me… ①Information security evangelist ②On-demand CISO/vCISO ③Industry speaker and socialite ①Director of Information Security Consulting @ Schillings ②Blogger – InfoRisk.io/Schillings.co.uk ③Give01Day Supporter! ④ f
  • 3. What is the General Data Protection Regulation? The purpose of the General Data Protection Regulation (“GDPR”) is to replace existing and incredibly outdated Data Protection legislation in-acted by various EU member-states with a single, unified regulation for protecting Personal Data. The Draft GDPR was introduced by the European Commission (“EC”) in January 2012 with the latest version of the draft approved by the European Parliament in March 2014. Given the fundamental change in Data Protection at EU-level, there is still much negotiation to take place and it is suspected that the final form will not be approved until late next year, with a further 2-year enforcement deadline. However, with over 4,000 proposed amendments to the original legislation organizations should be reviewing their current Data Protection and Information Security posture now in preparation for this significant regulatory change. This slide-deck will outline just some of the most substantial changes organizations need to be aware of. ① f
  • 4. Increased fines Currently, under the Data Protection Act in the UK, the maximum penalty for non-compliance is £500,000, although the ICO (Information Commissioners Office), the UK Authority for the Data Protection Act, has only issued a maximum fine of £250,000. Many believe that these thresholds are far to low, given the devastation a loss of data can cause and its potential to cause even greater harm as we adopt Cloud computing and the Internet of Things (“IoT”) The new General Data Protection Regulation will come with fines of up to 5% of annual group-wide revenue, or €100 million, whichever sum is greatest. This is a substantial change that all organizations should take on board when allocating budget and priority to Data Protection and Information Security ① f
  • 5. Notification requirements According to the latest draft of the GDPR, organizations will be required to notify the National Supervisory Authority of all data breaches without undue delay within 72 hours, in addition to notifying the affected individuals of data-loss, similar to certain US federal law on Data Protection. E.g. the state of California. In instances were data has been encrypted and is unreadable (and therefore not compromised in terms of its Confidentiality and Integrity) it may not be necessary to notify. Currently, one of the biggest reasons for organizations being fine is due to lost or stolen devices that do not employ encryption. This requirement to notify means that organizations can no longer brush data-loss incidents under the rug and increases the likelihood of significant reputation and financial harm in the event of data loss.
  • 6. Data Privacy Impact Assessments (DPIA) Both Data Controllers and Data Processors will be required to perform Data Privacy Impact Assessments (DPIAs) to identify how data handling procedures and processes (including what Personal Data is used for) could impact the safety of information associated to data-subjects, and overall compliance of that information under the GDPR This change will put in place greater administrative overhead to ensure compliance. Additionally, this change enforces Data Processors to become more responsible in ensuring Data Protection by mandating their compliance with the GDPR. This change aims to minimize Data Protection risk in the supply chain, which is often a cause of vulnerability that results in data-losses, which the Data Controller is accountable for.
  • 7. Mandatory appointment of Data Protection Officer (DPO) Organizations that process the personal information of 5,000 individuals or more annually, or maintain data processing as a core business function will be required to hire a Data Protection Officer (DPO) to oversee data processing operations. Importantly, to ensure severance from business politics and conflicts of interest, this individual will be given enhanced employment rights, including a minimum tenure of 4 years, full time and 2 years for a contractor. Organizations may hire a single DPO for the entire business. However, they must, in all cases, have knowledge and experience in Data Protection law. Public authorities will be required to appoint a DPO regardless of the number of individuals’ personal data they process.
  • 8. Application to non-EU organizations Organizations that are not based within the EU, but target EU citizens with goods and services will be required to comply with the GDPR.
  • 9. Application to Data Processors In the current Data Protection Act, Data Controllers are entirely accountable for the protection of Personal Data, even if some of that data is processed by third-party organizations acting as Data Processors. Under the GDPR Data Processors will be required to comply with the GDPR which means they share the liability of data-loss incidents and non-compliance.
  • 10. Application to Data Processors In the current Data Protection Act, Data Controllers are entirely accountable for the protection of Personal Data, even if some of that data is processed by third-party organizations acting as Data Processors. Under the GDPR Data Processors will be required to comply with the GDPR which means they share the liability of data-loss incidents and non-compliance.
  • 11. Thank you. Other changes to be aware of: 1. Right to be forgotten. Click here to see Select Committee report in July 2014. 1. Explicit Consent. Individuals are required to give consent for their data to be processed. David Prince, CISSP, CISM Director – Information Security Consulting, Schillings @RiskObscurity InfoRisk.io