SlideShare una empresa de Scribd logo
1 de 15
© 2016 IBM Corporation1
Why Britain’s decision to exit from the EU
actually makes complying with the GDPR even
more important for business today.
Donald Macfarlane (IBM)
Mark Williamson (Hanzo)
9.15 - 9.50 am
22 September 2016
General Data Protection Regulation
© 2016 IBM Corporation2
GDPR Summary & Obligations
Britain’s vote to exit the EU & GDPR Impact
Compliance Examples – current practice
Summary / Conclusions
Questions
Agenda
© 2016 IBM Corporation3
General Data Protection Regulation applies
from 25 May 2018
 The General Data Protection Regulation
(GDPR) was published on 4 May 2018, and
will be apply after a 2 year transition
period.
 Any organisation which “operates in” the
EU market from 25th May 2018.
 Creates a unified data protection law
framework for all EU countries.
 Non-compliance has the potential to lead
to huge fines and the clock is ticking.
© 2016 IBM Corporation4
 Right to Seek Information (Article 14)
 Right of Access by Data Subject (Article 15)
 Right to Rectification (Article 16)
 Right to Erasure (Article 17)
 Right to Restrict Processing (Article 18)
 Right of Data Portability (Article 20)
 Right to Object (Article 21)
GDPR
© 2016 IBM Corporation5
“Who cares, we are leaving
we do not need to worry
about this stuff….”
© 2016 IBM Corporation6
The GDPR is a game changer because of the
civil and criminal liability
Applies to organisations outside the EU
processing EU data subjects’ personal data.
Broad definition of personal data.
Will fundamentally change the way
organisations must protect, govern and know
their structured and unstructured data.
Euro 20 m or 4 % group turnover (worldwide).
© 2016 IBM Corporation7
GDPR: Good Practice
• Studies still indicate ~50 % business still unaware of
obligations/partial.
• Reputational damage / initial customer loss e.g. Talk Talk
plc/Sony etc
• Studies show that consumers trust ethical organisations more
and spend more with them.
• Individuals can sue for material and non-material damage
(distress).
• Not just the fine – you want to do this as you want to be seen
as a “good business”.
© 2016 IBM Corporation8
 23rd June 2016 Referendum Result – UK votes to leave the EU.
 Brexit Implication:
• GDPR will apply in 18 months whereas Article 50 will likely take 2 years
plus; and
• Whether UK in/or out any business processing EU citizens data.
• UK/International corporations trading with EU:
• Non EU members of the EEA e.g. Norway – GDPR implemented;
• EFTA member but not EEA e.g. Switzerland – Swiss DP very similar; or
• “WTO” type model (Canada) – partial adequacy c.f. USA “EU-US Privacy
Shield”
“It’s not fair we don’t like the EU legislation, we voted “out”, but it is being
forced upon us anyway….”
Impact of Brexit Vote
© 2016 IBM Corporation9
 Article 4: “Personal data" means any information relating to an identified or
identifiable natural person ("data subject"); an identifiable person is one who can
be identified, directly or indirectly, in particular by reference to an identifier such
as a name, an identification number, location data, online identifier or to one or
more factors specific to the physical, physiological, genetic, mental, economic,
cultural or social identity of that person.
 Email address, unique national identification number, tax, passport or identity
card, vehicle registration plate number, driver's license number, biometric data:
face, fingerprints, or handwriting, credit card numbers, date of birth an birthplace,
gender/race, genetic/medical information, telephone number, login name, screen
name, nickname, or handle, IP address (in some cases), geographical data,
qualifications, criminal record data, employment details….
In Reality
© 2016 IBM Corporation10
Where is the data?
• Web Pages
• Email
• SharePoint
• Wiki(s)
• Documents
• Sharing Platforms
• Customer Portals
• Know your customer platforms
• ECM systems
• Data Map and how is it accessed – via a browser?
Everywhere
© 2016 IBM Corporation11
 Right to Seek Information (Article 14)
 Right of Access by Data Subject (Article 15)
 Right to Rectification (Article 16)
 Right to Erasure (Article 17)
 Right to Restrict Processing (Article 18)
 Right of Data Portability (Article 20)
 Right to Object (Article 21)
GDPR
© 2016 IBM Corporation12
 Understanding where the data resides and keeping track of it
 Ability to perform your obligations, which means:
• Ability to report what you have;
• Ability to delete defensibly;
• Ability to place a block internally; and
• Right to receive an export.
• Business needs workable, efficient processes that allow people to do their day jobs.
What does it mean?
© 2016 IBM Corporation13
Question: Customer(s) reporting their PII on your corporate
site. What do you do?
• Capture all corporate sites legally defensible
• Identify the PII – search, extract
• Broaden the analysis to verify extent
• Generate Report
• Take Action
• Verify – appropriate action taken and rectified (control)
Best Practice Example 1
© 2016 IBM Corporation14
Question: Customer(s) requesting a copy of their data in
electronic format? What do you do?
• Capture all corporate sites/data - legally defensible
• Identify the PII – search, extract
• Generate an export (csv, xml)
Streamlined process and anticipates multiple data provisions
due to being prepared by knowing where the data resides
Best Practice Example 2
© 2016 IBM Corporation15
 No matter how we leave the EU, we will still be doing business with the EU.
 GDPR matters.
 With the right tools it need not be complex.
 People, Process and Technology.
Summary

Más contenido relacionado

La actualidad más candente

Data theft rules and regulations things you should know (pt.1)
Data theft rules and regulations  things you should know (pt.1)Data theft rules and regulations  things you should know (pt.1)
Data theft rules and regulations things you should know (pt.1)Faidepro
 
Social Media and the Law - by Tom Cowling
Social Media and the Law - by Tom CowlingSocial Media and the Law - by Tom Cowling
Social Media and the Law - by Tom CowlingiCrossing
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data OpportunityiCrossing
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in BerlinMailjet
 
Data Security and Data Governance: Foundation and Case Studies - November 4, ...
Data Security and Data Governance: Foundation and Case Studies - November 4, ...Data Security and Data Governance: Foundation and Case Studies - November 4, ...
Data Security and Data Governance: Foundation and Case Studies - November 4, ...Dr. Thiti Vacharasintopchai, ATSI-DX, CISA
 
Legal social ethical
Legal social ethicalLegal social ethical
Legal social ethicalSheetal Verma
 
scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04Jan Dhont
 
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.Steven Salter
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?VILT
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownAgile PR
 
GDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmGDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmChris White
 
GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?MediaPost
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?David Erdos
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsUlf Mattsson
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands legalandgeneral
 

La actualidad más candente (20)

Data theft rules and regulations things you should know (pt.1)
Data theft rules and regulations  things you should know (pt.1)Data theft rules and regulations  things you should know (pt.1)
Data theft rules and regulations things you should know (pt.1)
 
Social Media and the Law - by Tom Cowling
Social Media and the Law - by Tom CowlingSocial Media and the Law - by Tom Cowling
Social Media and the Law - by Tom Cowling
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data Opportunity
 
ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
Is Poland Ready for GDPR?
Is Poland Ready for GDPR? Is Poland Ready for GDPR?
Is Poland Ready for GDPR?
 
Data Security and Data Governance: Foundation and Case Studies - November 4, ...
Data Security and Data Governance: Foundation and Case Studies - November 4, ...Data Security and Data Governance: Foundation and Case Studies - November 4, ...
Data Security and Data Governance: Foundation and Case Studies - November 4, ...
 
Legal social ethical
Legal social ethicalLegal social ethical
Legal social ethical
 
scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04scce-cep-2015-06-Dhont-1-04
scce-cep-2015-06-Dhont-1-04
 
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 
GDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmGDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, Ecosystm
 
GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
 

Destacado

Sistemas de reparación #TerritorioHELLA
Sistemas de reparación #TerritorioHELLASistemas de reparación #TerritorioHELLA
Sistemas de reparación #TerritorioHELLAHELLA Spain
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowDavid Erdos
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationGhostery, Inc.
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
The Impact of the General Data Protection Regulation - 10th May 2016
The Impact of the General Data Protection Regulation - 10th May 2016The Impact of the General Data Protection Regulation - 10th May 2016
The Impact of the General Data Protection Regulation - 10th May 2016IISPEastMids
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPRIT Governance Ltd
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
Best Music
Best MusicBest Music
Best Musicalis001
 
MOOCs and open practices PGDip presentation
MOOCs and open practices PGDip presentationMOOCs and open practices PGDip presentation
MOOCs and open practices PGDip presentationmichaelgloveresearch
 
EL CARTERO GUILLOT
EL CARTERO GUILLOTEL CARTERO GUILLOT
EL CARTERO GUILLOTepc-florida
 
My one year journey into behavioral economics
My one year journey into behavioral economicsMy one year journey into behavioral economics
My one year journey into behavioral economicsmatthewstergiou
 
Pediatric Nurse Practitioner
Pediatric Nurse PractitionerPediatric Nurse Practitioner
Pediatric Nurse Practitionersantanaarcher15
 
CHAVELA QUIERE IR A LA ESCUELA ACTIVIDADES
CHAVELA QUIERE IR A LA ESCUELA ACTIVIDADESCHAVELA QUIERE IR A LA ESCUELA ACTIVIDADES
CHAVELA QUIERE IR A LA ESCUELA ACTIVIDADESepc-florida
 

Destacado (15)

Sistemas de reparación #TerritorioHELLA
Sistemas de reparación #TerritorioHELLASistemas de reparación #TerritorioHELLA
Sistemas de reparación #TerritorioHELLA
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information Flow
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
The Impact of the General Data Protection Regulation - 10th May 2016
The Impact of the General Data Protection Regulation - 10th May 2016The Impact of the General Data Protection Regulation - 10th May 2016
The Impact of the General Data Protection Regulation - 10th May 2016
 
Data Breaches and the EU GDPR
Data Breaches and the EU GDPRData Breaches and the EU GDPR
Data Breaches and the EU GDPR
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
Soccer
SoccerSoccer
Soccer
 
Best Music
Best MusicBest Music
Best Music
 
MOOCs and open practices PGDip presentation
MOOCs and open practices PGDip presentationMOOCs and open practices PGDip presentation
MOOCs and open practices PGDip presentation
 
BLENDED LEREN
BLENDED LERENBLENDED LEREN
BLENDED LEREN
 
EL CARTERO GUILLOT
EL CARTERO GUILLOTEL CARTERO GUILLOT
EL CARTERO GUILLOT
 
My one year journey into behavioral economics
My one year journey into behavioral economicsMy one year journey into behavioral economics
My one year journey into behavioral economics
 
Pediatric Nurse Practitioner
Pediatric Nurse PractitionerPediatric Nurse Practitioner
Pediatric Nurse Practitioner
 
CHAVELA QUIERE IR A LA ESCUELA ACTIVIDADES
CHAVELA QUIERE IR A LA ESCUELA ACTIVIDADESCHAVELA QUIERE IR A LA ESCUELA ACTIVIDADES
CHAVELA QUIERE IR A LA ESCUELA ACTIVIDADES
 

Similar a Data Protection and Comnpliance with the GDPR Event 22 september 2016

Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-finalDr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalDr. Donald Macfarlane
 
GDPR training
GDPR training GDPR training
GDPR training ASL
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationJoseph V. Moreno
 
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce OutserveWeb
 
DV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal LandscapeDV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal LandscapeTealium
 
Explain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdprExplain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdprPierre Feillet
 
GDPR vs Blockchain – A Paradox, Challenge and an Opportunity
GDPR vs Blockchain – A Paradox, Challenge and an OpportunityGDPR vs Blockchain – A Paradox, Challenge and an Opportunity
GDPR vs Blockchain – A Paradox, Challenge and an OpportunityAffiliate Summit
 
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc
 
CASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disasterCASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disasterB2B Marketing
 
Why the new data laws are good for UX
Why the new data laws are good for UXWhy the new data laws are good for UX
Why the new data laws are good for UXjreay
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.James Seville
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 

Similar a Data Protection and Comnpliance with the GDPR Event 22 september 2016 (20)

Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
GDPR training
GDPR training GDPR training
GDPR training
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
GDPR Information
GDPR InformationGDPR Information
GDPR Information
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
Challenge Academy June 2018 - Digital Marketing, Web Traffic and Ecommerce
 
DV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal LandscapeDV 2016: Making Sense of the Current Legal Landscape
DV 2016: Making Sense of the Current Legal Landscape
 
Explain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdprExplain your algorithmic decisions for gdpr
Explain your algorithmic decisions for gdpr
 
GPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-RightGPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-Right
 
GDPR vs Blockchain – A Paradox, Challenge and an Opportunity
GDPR vs Blockchain – A Paradox, Challenge and an OpportunityGDPR vs Blockchain – A Paradox, Challenge and an Opportunity
GDPR vs Blockchain – A Paradox, Challenge and an Opportunity
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
 
CASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disasterCASE STUDY: New EU legislation: how to avoid data disaster
CASE STUDY: New EU legislation: how to avoid data disaster
 
Why the new data laws are good for UX
Why the new data laws are good for UXWhy the new data laws are good for UX
Why the new data laws are good for UX
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.GDPR How ready are you? The What, Why and How.
GDPR How ready are you? The What, Why and How.
 
GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 

Último

ALSO dropshipping via API with DroFx.pptx
ALSO dropshipping via API with DroFx.pptxALSO dropshipping via API with DroFx.pptx
ALSO dropshipping via API with DroFx.pptxolyaivanovalion
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxolyaivanovalion
 
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779Delhi Call girls
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxolyaivanovalion
 
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...shivangimorya083
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxolyaivanovalion
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfMarinCaroMartnezBerg
 
Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...shambhavirathore45
 
BabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxBabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxolyaivanovalion
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...amitlee9823
 
CALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service OnlineCALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service Onlineanilsa9823
 
Halmar dropshipping via API with DroFx
Halmar  dropshipping  via API with DroFxHalmar  dropshipping  via API with DroFx
Halmar dropshipping via API with DroFxolyaivanovalion
 
CebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxCebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxolyaivanovalion
 
VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130
VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130
VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130Suhani Kapoor
 
Mature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptxMature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptxolyaivanovalion
 
Midocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxMidocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxolyaivanovalion
 
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxBPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxMohammedJunaid861692
 
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfAccredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfadriantubila
 

Último (20)

ALSO dropshipping via API with DroFx.pptx
ALSO dropshipping via API with DroFx.pptxALSO dropshipping via API with DroFx.pptx
ALSO dropshipping via API with DroFx.pptx
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFx
 
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
Best VIP Call Girls Noida Sector 22 Call Me: 8448380779
 
Ravak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptxRavak dropshipping via API with DroFx.pptx
Ravak dropshipping via API with DroFx.pptx
 
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...Vip Model  Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
Vip Model Call Girls (Delhi) Karol Bagh 9711199171✔️Body to body massage wit...
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptx
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
 
Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...Determinants of health, dimensions of health, positive health and spectrum of...
Determinants of health, dimensions of health, positive health and spectrum of...
 
꧁❤ Aerocity Call Girls Service Aerocity Delhi ❤꧂ 9999965857 ☎️ Hard And Sexy ...
꧁❤ Aerocity Call Girls Service Aerocity Delhi ❤꧂ 9999965857 ☎️ Hard And Sexy ...꧁❤ Aerocity Call Girls Service Aerocity Delhi ❤꧂ 9999965857 ☎️ Hard And Sexy ...
꧁❤ Aerocity Call Girls Service Aerocity Delhi ❤꧂ 9999965857 ☎️ Hard And Sexy ...
 
BabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptxBabyOno dropshipping via API with DroFx.pptx
BabyOno dropshipping via API with DroFx.pptx
 
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Junnasandra Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
CALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service OnlineCALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service Online
CALL ON ➥8923113531 🔝Call Girls Chinhat Lucknow best sexual service Online
 
Halmar dropshipping via API with DroFx
Halmar  dropshipping  via API with DroFxHalmar  dropshipping  via API with DroFx
Halmar dropshipping via API with DroFx
 
CebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptxCebaBaby dropshipping via API with DroFX.pptx
CebaBaby dropshipping via API with DroFX.pptx
 
Sampling (random) method and Non random.ppt
Sampling (random) method and Non random.pptSampling (random) method and Non random.ppt
Sampling (random) method and Non random.ppt
 
VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130
VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130
VIP Call Girls Service Miyapur Hyderabad Call +91-8250192130
 
Mature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptxMature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptx
 
Midocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxMidocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFx
 
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxBPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
 
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdfAccredited-Transport-Cooperatives-Jan-2021-Web.pdf
Accredited-Transport-Cooperatives-Jan-2021-Web.pdf
 

Data Protection and Comnpliance with the GDPR Event 22 september 2016

  • 1. © 2016 IBM Corporation1 Why Britain’s decision to exit from the EU actually makes complying with the GDPR even more important for business today. Donald Macfarlane (IBM) Mark Williamson (Hanzo) 9.15 - 9.50 am 22 September 2016 General Data Protection Regulation
  • 2. © 2016 IBM Corporation2 GDPR Summary & Obligations Britain’s vote to exit the EU & GDPR Impact Compliance Examples – current practice Summary / Conclusions Questions Agenda
  • 3. © 2016 IBM Corporation3 General Data Protection Regulation applies from 25 May 2018  The General Data Protection Regulation (GDPR) was published on 4 May 2018, and will be apply after a 2 year transition period.  Any organisation which “operates in” the EU market from 25th May 2018.  Creates a unified data protection law framework for all EU countries.  Non-compliance has the potential to lead to huge fines and the clock is ticking.
  • 4. © 2016 IBM Corporation4  Right to Seek Information (Article 14)  Right of Access by Data Subject (Article 15)  Right to Rectification (Article 16)  Right to Erasure (Article 17)  Right to Restrict Processing (Article 18)  Right of Data Portability (Article 20)  Right to Object (Article 21) GDPR
  • 5. © 2016 IBM Corporation5 “Who cares, we are leaving we do not need to worry about this stuff….”
  • 6. © 2016 IBM Corporation6 The GDPR is a game changer because of the civil and criminal liability Applies to organisations outside the EU processing EU data subjects’ personal data. Broad definition of personal data. Will fundamentally change the way organisations must protect, govern and know their structured and unstructured data. Euro 20 m or 4 % group turnover (worldwide).
  • 7. © 2016 IBM Corporation7 GDPR: Good Practice • Studies still indicate ~50 % business still unaware of obligations/partial. • Reputational damage / initial customer loss e.g. Talk Talk plc/Sony etc • Studies show that consumers trust ethical organisations more and spend more with them. • Individuals can sue for material and non-material damage (distress). • Not just the fine – you want to do this as you want to be seen as a “good business”.
  • 8. © 2016 IBM Corporation8  23rd June 2016 Referendum Result – UK votes to leave the EU.  Brexit Implication: • GDPR will apply in 18 months whereas Article 50 will likely take 2 years plus; and • Whether UK in/or out any business processing EU citizens data. • UK/International corporations trading with EU: • Non EU members of the EEA e.g. Norway – GDPR implemented; • EFTA member but not EEA e.g. Switzerland – Swiss DP very similar; or • “WTO” type model (Canada) – partial adequacy c.f. USA “EU-US Privacy Shield” “It’s not fair we don’t like the EU legislation, we voted “out”, but it is being forced upon us anyway….” Impact of Brexit Vote
  • 9. © 2016 IBM Corporation9  Article 4: “Personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.  Email address, unique national identification number, tax, passport or identity card, vehicle registration plate number, driver's license number, biometric data: face, fingerprints, or handwriting, credit card numbers, date of birth an birthplace, gender/race, genetic/medical information, telephone number, login name, screen name, nickname, or handle, IP address (in some cases), geographical data, qualifications, criminal record data, employment details…. In Reality
  • 10. © 2016 IBM Corporation10 Where is the data? • Web Pages • Email • SharePoint • Wiki(s) • Documents • Sharing Platforms • Customer Portals • Know your customer platforms • ECM systems • Data Map and how is it accessed – via a browser? Everywhere
  • 11. © 2016 IBM Corporation11  Right to Seek Information (Article 14)  Right of Access by Data Subject (Article 15)  Right to Rectification (Article 16)  Right to Erasure (Article 17)  Right to Restrict Processing (Article 18)  Right of Data Portability (Article 20)  Right to Object (Article 21) GDPR
  • 12. © 2016 IBM Corporation12  Understanding where the data resides and keeping track of it  Ability to perform your obligations, which means: • Ability to report what you have; • Ability to delete defensibly; • Ability to place a block internally; and • Right to receive an export. • Business needs workable, efficient processes that allow people to do their day jobs. What does it mean?
  • 13. © 2016 IBM Corporation13 Question: Customer(s) reporting their PII on your corporate site. What do you do? • Capture all corporate sites legally defensible • Identify the PII – search, extract • Broaden the analysis to verify extent • Generate Report • Take Action • Verify – appropriate action taken and rectified (control) Best Practice Example 1
  • 14. © 2016 IBM Corporation14 Question: Customer(s) requesting a copy of their data in electronic format? What do you do? • Capture all corporate sites/data - legally defensible • Identify the PII – search, extract • Generate an export (csv, xml) Streamlined process and anticipates multiple data provisions due to being prepared by knowing where the data resides Best Practice Example 2
  • 15. © 2016 IBM Corporation15  No matter how we leave the EU, we will still be doing business with the EU.  GDPR matters.  With the right tools it need not be complex.  People, Process and Technology. Summary

Notas del editor

  1. Extra-territorial i.e. applies to organisations outside the EU processing EU data subjects’ personal data and touches “controllers” AND “processors” assuming we leave the EU UK organisations will still be affected. Broad definition of personal data, includes data that directly or indirectly identifies or makes identifiable a data subject such as online identifiers, IP addresses and location data etc.
  2. Business Awareness – low therefore work for lawyers Risk Aim
  3. Trend is towards a digital economy with data protection across the world
  4. What does that actually mean
  5. Individuals have a right to privacy - “private and family life, his home and his correspondence” (Article 8 ECHR) Individuals have right to protection of personal data - “Everyone has the right to the protection of personal data concerning him or her” (Article 8 ECFR) Specifically grants data subjects with the rights to access, modify, update or ask for deletion of such data e.g. right to know what data is gathered or stored about you, to access this and request modification/deletion Data protection (narrower) gives individuals: Right to know what personal data is collected, on what legal grounds, how it is used, for how long it used and kept, and by whom. Specifically grants data subjects with the right to access, modify, update or ask for deletion of their data
  6. All know corporate data is widespread