SlideShare una empresa de Scribd logo
1 de 18
Achieving Compliance with the
General Data Protection Regulation
(GDPR)
Project GDPR
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 1
General Data Protection
Regulation (GDPR)
by Dr Sami Zahran
July 2017
Introduction to the:
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 2
Contents
1.Motivation & Rationale (why ?)
2. Scope – The target change (What ?)
3. Programme of Change (How ?)
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 3
1. Motivation & Rationale (why ?)
 The existing legislative landscape for data protection across the European Union
is fragmented, causing confusion to individuals and businesses.
 The current regulations in place to protect EU citizen data are out of date and
have long been overtaken both by technology and by way of the way data is
stored and secured.
 The outgoing legislation (EU Data Protection Directive 95/46/ec- came in force
1955, and since then the way data is collected and used has changed
fundamentally.
 The incoming General Data Protection (GDPR) will address the gap and make EU
privacy and data laws fit-for-purpose in the digital age – harmonising data
protection laws in the EU.
 GDPR is a regulation, and when it comes into effect in spring 2018, it will
directly applicable in all EU members. From May 2018, it will be directly
applicable in all in all EU member states as a single laws.
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 4
GDPR Privacy Principles
GDPR Six Privacy Principles:
1) Lawfulness, fairness and transparency (*)
2) Purpose limitations
3) Data minimisation
4) Accuracy
5) Storage limitations
6) Integrity and confidentiality
(*) Transparency: (Tell the subject what data processing will be done)
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 5
The six Principles of GDPR
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 6
Scope – What information does the GDPR apply to (GDPR versus DPA)?
The GDPR rules apply to “personal data”
 GDPR’s definition of personal data includes online plus any enablers of
personal identification information–e.g. IP address –
 The new rules reflect changes in technology and the way organizations collect
information about people.
 Any information that falls within the scope of the DPA (Data Protection Act),
will also fall within the scope of GDPR.
 The GDPR applies to both automated personal data and to manual filing
systems. (Wider DPA definition)
 Personal data that has been pseudonymised – e.g. key-coded
 GDPR refers to sensitive personal data as “special categories of personal
data” which also include generic data, and biometric data when processed
can lead to identify an individual
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 7
Contents
1. Motivation & Rationale (why ?)
2.Scope – The target change (What ?)
3. Programme of Change (How ?)
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 8
The target change (New Capabilities)
Key new capabilities to be created:
1. Individuals’ rights
2. The right to be informed
3. The right of access
4. The right to recertification
5. The right to erasure
6. The right to restrict processing
7. The right ti data portability
8. The right to object
9. Right related to automated decision making and profiling
10. Accountability and governance
11. Breach notification
12. Transfer of data
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 9
GDPR Requirements of Personal Data
GPDR requires that Personal Data shall be:
a) Processed lawfully, fairly and in a transparent manner.
b) Collected for specified, explicit and legitimate purposes and no
further.
c) Adequate, relevant and limited to what is necessary.
d) Accurate and where necessary kept up-to date.
e) Kept in a form that permits identification of data subjects for
no longer than is necessary (except for archiving purposes)
f) Processed in a way that ensures appropriate security of the
personal data (e.g. protection against unauthorized or unlawful
processing)
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 10
Target areas for assessment and remediation
Key Areas to be assessed and remediated: (1/2)
1. Lawful processing
2. Consent
3. Children’s personal data
4. Individuals’ rights
5. The right to be informed
6. The right of access
7. The right to recertification
8. The right to restrict processing
9. The right to data portability
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 11
Key Areas to be assessed and remediated: (2/2)
10. The right to object
11. Rights related to automated decision making and profiling
12. Accountability and governance
13. Data protection impact assessments.
14. Breach notification
15. Transfer of data
16. National derogations
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 12
Target areas for assessment and remediation
Contents
1. Motivation & Rationale (why ?)
2. Scope – The target change (What ?)
3.GDPR: A Programme of Change (How ?)
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 13
GDPR - Programme of Change
(Main Features)
 Corporate-wide Change/Multi-Sites - Covers all business areas and all locations
 Regulatory - mandatory
 Fixed end-date - date cannot be moved
 Critical - if target date is missed, financial penalties will be imposed
 New procedures - for recording and processing people data
 Business Process Changes - remediating current processes and creating new
 People involvement - awareness and training, new role sand responsibilities
 Technology - possible changes to current applications, possible new tools
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 14
GDPR - Programme of Change
(Governance levels)
Level-1) Corporate GDPR Control Board
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 15
Level-2) Business Unit (BU) project Control Board(s)
Level-3) Business Unit (BU) Project Manager(s)
Level-4) Team Leader(s)
GDPR - Programme of Change
(Governance levels)
Level-1) Corporate GDPR Control Board
Senior management financial support and oversight of the overall progress of GDPR and
resolving major issues
Level-2) Business Unit (BU) project Control Board:
Project Control Board to support the project manager by providing advice and resolving
project level issues
Level-3) Business Unit (BU) Project Manager:
Project Manager to conduct the day-today running of the project through a number of team
leaders taking responsibility of one or more workpackages
Level-4) Team Leaders:
Take responsibility for one or more workpackages (or sprints)
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 16
GDPR - Programme of Change
(Programme-Level Management and Support)
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 17
• Central Governance: Central (corporate level) GDPR Control Board
• Central admin support: programme support office (PMO)
• Strategic Alignment: with the company strategy
• Programme & Project Assurance: Independent Quality Assurance of the various projects
• Accountability Clear roles and responsibilities (at the programme and the projects level)
• management of projects, stakeholders and suppliers is in place (at the programme and the projects level)
• Integration of the outputs of the various projects (this is critical for the success of the programme)
• Finances: Monitoring the finance statuses of the individual projects, and collectively of the
programme
• Planning: programme level outline plan and projects-levels detailed plans
End
End of the Quick Intro to DGPR by Dr Sami Zahran
GDPR Remediation Programme .. Intro by Dr. Sami Zahran 18

Más contenido relacionado

La actualidad más candente

DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
GDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityGDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityDean Sappey
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution Google
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideZymplify
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparationPromapp Solutions
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017Amarach Research
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non expertsClaudio Bolla, CISM
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 

La actualidad más candente (20)

DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
GDPR From Implementation to Opportunity
GDPR From Implementation to OpportunityGDPR From Implementation to Opportunity
GDPR From Implementation to Opportunity
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
What does GDPR mean for your charity?
What does GDPR mean for your charity?What does GDPR mean for your charity?
What does GDPR mean for your charity?
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 

Similar a Achieving GDPR Compliance with a Remediation Programme

Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project DEFeND Project
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaperJim Wilson
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018Dean Evans
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Codemotion
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
The Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsThe Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsHubilo
 
All you need to know about GDPR
All you need to know about GDPRAll you need to know about GDPR
All you need to know about GDPRHubilo
 
ICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPRICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPRBenjamin Dibble
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceMongoDB
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To ConsiderSymantec
 
GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadVisitor Analytics
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRzayadeen2003
 

Similar a Achieving GDPR Compliance with a Remediation Programme (20)

Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018
 
DPO Circle 2018
DPO Circle 2018 DPO Circle 2018
DPO Circle 2018
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
GDPR
GDPRGDPR
GDPR
 
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
The Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsThe Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event Professionals
 
All you need to know about GDPR
All you need to know about GDPRAll you need to know about GDPR
All you need to know about GDPR
 
GDPR presentation
GDPR presentationGDPR presentation
GDPR presentation
 
ICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPRICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPR
 
GDPR Preparing for-the-gdpr-12-steps
GDPR Preparing for-the-gdpr-12-stepsGDPR Preparing for-the-gdpr-12-steps
GDPR Preparing for-the-gdpr-12-steps
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To Consider
 
GDPR How to get started?
GDPR  How to get started?GDPR  How to get started?
GDPR How to get started?
 
GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free Download
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 

Más de Dr. Sami Zahran

The Agile Project Manager
The Agile Project Manager The Agile Project Manager
The Agile Project Manager Dr. Sami Zahran
 
Enterise Tranformation why what-how by sami zahran
Enterise Tranformation why what-how by sami zahranEnterise Tranformation why what-how by sami zahran
Enterise Tranformation why what-how by sami zahranDr. Sami Zahran
 
Zahran's 10 minute introduction to PRINCE2
Zahran's 10 minute introduction to PRINCE2Zahran's 10 minute introduction to PRINCE2
Zahran's 10 minute introduction to PRINCE2Dr. Sami Zahran
 
Zahran's 4 p dimentions of quality
Zahran's  4 p dimentions of quality  Zahran's  4 p dimentions of quality
Zahran's 4 p dimentions of quality Dr. Sami Zahran
 
Sami Zahran Quality Gates
Sami Zahran Quality GatesSami Zahran Quality Gates
Sami Zahran Quality GatesDr. Sami Zahran
 
Patterns for the Enterprise Process Architecture
Patterns for the Enterprise Process Architecture Patterns for the Enterprise Process Architecture
Patterns for the Enterprise Process Architecture Dr. Sami Zahran
 

Más de Dr. Sami Zahran (7)

The Agile Project Manager
The Agile Project Manager The Agile Project Manager
The Agile Project Manager
 
PRINCE2 2017 Updates
PRINCE2 2017 UpdatesPRINCE2 2017 Updates
PRINCE2 2017 Updates
 
Enterise Tranformation why what-how by sami zahran
Enterise Tranformation why what-how by sami zahranEnterise Tranformation why what-how by sami zahran
Enterise Tranformation why what-how by sami zahran
 
Zahran's 10 minute introduction to PRINCE2
Zahran's 10 minute introduction to PRINCE2Zahran's 10 minute introduction to PRINCE2
Zahran's 10 minute introduction to PRINCE2
 
Zahran's 4 p dimentions of quality
Zahran's  4 p dimentions of quality  Zahran's  4 p dimentions of quality
Zahran's 4 p dimentions of quality
 
Sami Zahran Quality Gates
Sami Zahran Quality GatesSami Zahran Quality Gates
Sami Zahran Quality Gates
 
Patterns for the Enterprise Process Architecture
Patterns for the Enterprise Process Architecture Patterns for the Enterprise Process Architecture
Patterns for the Enterprise Process Architecture
 

Último

VidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxVidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxolyaivanovalion
 
Midocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxMidocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxolyaivanovalion
 
B2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docxB2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docxStephen266013
 
Mature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptxMature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptxolyaivanovalion
 
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...Suhani Kapoor
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxolyaivanovalion
 
April 2024 - Crypto Market Report's Analysis
April 2024 - Crypto Market Report's AnalysisApril 2024 - Crypto Market Report's Analysis
April 2024 - Crypto Market Report's Analysismanisha194592
 
Low Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service Bhilai
Low Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service BhilaiLow Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service Bhilai
Low Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service BhilaiSuhani Kapoor
 
Smarteg dropshipping via API with DroFx.pptx
Smarteg dropshipping via API with DroFx.pptxSmarteg dropshipping via API with DroFx.pptx
Smarteg dropshipping via API with DroFx.pptxolyaivanovalion
 
(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Service
(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Service(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Service
(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Serviceranjana rawat
 
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al BarshaAl Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al BarshaAroojKhan71
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfMarinCaroMartnezBerg
 
Unveiling Insights: The Role of a Data Analyst
Unveiling Insights: The Role of a Data AnalystUnveiling Insights: The Role of a Data Analyst
Unveiling Insights: The Role of a Data AnalystSamantha Rae Coolbeth
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改
代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改
代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改atducpo
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxolyaivanovalion
 
04242024_CCC TUG_Joins and Relationships
04242024_CCC TUG_Joins and Relationships04242024_CCC TUG_Joins and Relationships
04242024_CCC TUG_Joins and Relationshipsccctableauusergroup
 
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxBPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxMohammedJunaid861692
 

Último (20)

VidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptxVidaXL dropshipping via API with DroFx.pptx
VidaXL dropshipping via API with DroFx.pptx
 
Midocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFxMidocean dropshipping via API with DroFx
Midocean dropshipping via API with DroFx
 
B2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docxB2 Creative Industry Response Evaluation.docx
B2 Creative Industry Response Evaluation.docx
 
Mature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptxMature dropshipping via API with DroFx.pptx
Mature dropshipping via API with DroFx.pptx
 
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
VIP High Class Call Girls Jamshedpur Anushka 8250192130 Independent Escort Se...
 
BigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptxBigBuy dropshipping via API with DroFx.pptx
BigBuy dropshipping via API with DroFx.pptx
 
April 2024 - Crypto Market Report's Analysis
April 2024 - Crypto Market Report's AnalysisApril 2024 - Crypto Market Report's Analysis
April 2024 - Crypto Market Report's Analysis
 
Low Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service Bhilai
Low Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service BhilaiLow Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service Bhilai
Low Rate Call Girls Bhilai Anika 8250192130 Independent Escort Service Bhilai
 
Smarteg dropshipping via API with DroFx.pptx
Smarteg dropshipping via API with DroFx.pptxSmarteg dropshipping via API with DroFx.pptx
Smarteg dropshipping via API with DroFx.pptx
 
(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Service
(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Service(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Service
(PARI) Call Girls Wanowrie ( 7001035870 ) HI-Fi Pune Escorts Service
 
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al BarshaAl Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
Al Barsha Escorts $#$ O565212860 $#$ Escort Service In Al Barsha
 
FESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdfFESE Capital Markets Fact Sheet 2024 Q1.pdf
FESE Capital Markets Fact Sheet 2024 Q1.pdf
 
Unveiling Insights: The Role of a Data Analyst
Unveiling Insights: The Role of a Data AnalystUnveiling Insights: The Role of a Data Analyst
Unveiling Insights: The Role of a Data Analyst
 
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in Kishangarh
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in  KishangarhDelhi 99530 vip 56974 Genuine Escort Service Call Girls in  Kishangarh
Delhi 99530 vip 56974 Genuine Escort Service Call Girls in Kishangarh
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改
代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改
代办国外大学文凭《原版美国UCLA文凭证书》加州大学洛杉矶分校毕业证制作成绩单修改
 
Sampling (random) method and Non random.ppt
Sampling (random) method and Non random.pptSampling (random) method and Non random.ppt
Sampling (random) method and Non random.ppt
 
Edukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFxEdukaciniai dropshipping via API with DroFx
Edukaciniai dropshipping via API with DroFx
 
04242024_CCC TUG_Joins and Relationships
04242024_CCC TUG_Joins and Relationships04242024_CCC TUG_Joins and Relationships
04242024_CCC TUG_Joins and Relationships
 
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptxBPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
BPAC WITH UFSBI GENERAL PRESENTATION 18_05_2017-1.pptx
 

Achieving GDPR Compliance with a Remediation Programme

  • 1. Achieving Compliance with the General Data Protection Regulation (GDPR) Project GDPR GDPR Remediation Programme .. Intro by Dr. Sami Zahran 1
  • 2. General Data Protection Regulation (GDPR) by Dr Sami Zahran July 2017 Introduction to the: GDPR Remediation Programme .. Intro by Dr. Sami Zahran 2
  • 3. Contents 1.Motivation & Rationale (why ?) 2. Scope – The target change (What ?) 3. Programme of Change (How ?) GDPR Remediation Programme .. Intro by Dr. Sami Zahran 3
  • 4. 1. Motivation & Rationale (why ?)  The existing legislative landscape for data protection across the European Union is fragmented, causing confusion to individuals and businesses.  The current regulations in place to protect EU citizen data are out of date and have long been overtaken both by technology and by way of the way data is stored and secured.  The outgoing legislation (EU Data Protection Directive 95/46/ec- came in force 1955, and since then the way data is collected and used has changed fundamentally.  The incoming General Data Protection (GDPR) will address the gap and make EU privacy and data laws fit-for-purpose in the digital age – harmonising data protection laws in the EU.  GDPR is a regulation, and when it comes into effect in spring 2018, it will directly applicable in all EU members. From May 2018, it will be directly applicable in all in all EU member states as a single laws. GDPR Remediation Programme .. Intro by Dr. Sami Zahran 4
  • 5. GDPR Privacy Principles GDPR Six Privacy Principles: 1) Lawfulness, fairness and transparency (*) 2) Purpose limitations 3) Data minimisation 4) Accuracy 5) Storage limitations 6) Integrity and confidentiality (*) Transparency: (Tell the subject what data processing will be done) GDPR Remediation Programme .. Intro by Dr. Sami Zahran 5
  • 6. The six Principles of GDPR GDPR Remediation Programme .. Intro by Dr. Sami Zahran 6
  • 7. Scope – What information does the GDPR apply to (GDPR versus DPA)? The GDPR rules apply to “personal data”  GDPR’s definition of personal data includes online plus any enablers of personal identification information–e.g. IP address –  The new rules reflect changes in technology and the way organizations collect information about people.  Any information that falls within the scope of the DPA (Data Protection Act), will also fall within the scope of GDPR.  The GDPR applies to both automated personal data and to manual filing systems. (Wider DPA definition)  Personal data that has been pseudonymised – e.g. key-coded  GDPR refers to sensitive personal data as “special categories of personal data” which also include generic data, and biometric data when processed can lead to identify an individual GDPR Remediation Programme .. Intro by Dr. Sami Zahran 7
  • 8. Contents 1. Motivation & Rationale (why ?) 2.Scope – The target change (What ?) 3. Programme of Change (How ?) GDPR Remediation Programme .. Intro by Dr. Sami Zahran 8
  • 9. The target change (New Capabilities) Key new capabilities to be created: 1. Individuals’ rights 2. The right to be informed 3. The right of access 4. The right to recertification 5. The right to erasure 6. The right to restrict processing 7. The right ti data portability 8. The right to object 9. Right related to automated decision making and profiling 10. Accountability and governance 11. Breach notification 12. Transfer of data GDPR Remediation Programme .. Intro by Dr. Sami Zahran 9
  • 10. GDPR Requirements of Personal Data GPDR requires that Personal Data shall be: a) Processed lawfully, fairly and in a transparent manner. b) Collected for specified, explicit and legitimate purposes and no further. c) Adequate, relevant and limited to what is necessary. d) Accurate and where necessary kept up-to date. e) Kept in a form that permits identification of data subjects for no longer than is necessary (except for archiving purposes) f) Processed in a way that ensures appropriate security of the personal data (e.g. protection against unauthorized or unlawful processing) GDPR Remediation Programme .. Intro by Dr. Sami Zahran 10
  • 11. Target areas for assessment and remediation Key Areas to be assessed and remediated: (1/2) 1. Lawful processing 2. Consent 3. Children’s personal data 4. Individuals’ rights 5. The right to be informed 6. The right of access 7. The right to recertification 8. The right to restrict processing 9. The right to data portability GDPR Remediation Programme .. Intro by Dr. Sami Zahran 11
  • 12. Key Areas to be assessed and remediated: (2/2) 10. The right to object 11. Rights related to automated decision making and profiling 12. Accountability and governance 13. Data protection impact assessments. 14. Breach notification 15. Transfer of data 16. National derogations GDPR Remediation Programme .. Intro by Dr. Sami Zahran 12 Target areas for assessment and remediation
  • 13. Contents 1. Motivation & Rationale (why ?) 2. Scope – The target change (What ?) 3.GDPR: A Programme of Change (How ?) GDPR Remediation Programme .. Intro by Dr. Sami Zahran 13
  • 14. GDPR - Programme of Change (Main Features)  Corporate-wide Change/Multi-Sites - Covers all business areas and all locations  Regulatory - mandatory  Fixed end-date - date cannot be moved  Critical - if target date is missed, financial penalties will be imposed  New procedures - for recording and processing people data  Business Process Changes - remediating current processes and creating new  People involvement - awareness and training, new role sand responsibilities  Technology - possible changes to current applications, possible new tools GDPR Remediation Programme .. Intro by Dr. Sami Zahran 14
  • 15. GDPR - Programme of Change (Governance levels) Level-1) Corporate GDPR Control Board GDPR Remediation Programme .. Intro by Dr. Sami Zahran 15 Level-2) Business Unit (BU) project Control Board(s) Level-3) Business Unit (BU) Project Manager(s) Level-4) Team Leader(s)
  • 16. GDPR - Programme of Change (Governance levels) Level-1) Corporate GDPR Control Board Senior management financial support and oversight of the overall progress of GDPR and resolving major issues Level-2) Business Unit (BU) project Control Board: Project Control Board to support the project manager by providing advice and resolving project level issues Level-3) Business Unit (BU) Project Manager: Project Manager to conduct the day-today running of the project through a number of team leaders taking responsibility of one or more workpackages Level-4) Team Leaders: Take responsibility for one or more workpackages (or sprints) GDPR Remediation Programme .. Intro by Dr. Sami Zahran 16
  • 17. GDPR - Programme of Change (Programme-Level Management and Support) GDPR Remediation Programme .. Intro by Dr. Sami Zahran 17 • Central Governance: Central (corporate level) GDPR Control Board • Central admin support: programme support office (PMO) • Strategic Alignment: with the company strategy • Programme & Project Assurance: Independent Quality Assurance of the various projects • Accountability Clear roles and responsibilities (at the programme and the projects level) • management of projects, stakeholders and suppliers is in place (at the programme and the projects level) • Integration of the outputs of the various projects (this is critical for the success of the programme) • Finances: Monitoring the finance statuses of the individual projects, and collectively of the programme • Planning: programme level outline plan and projects-levels detailed plans
  • 18. End End of the Quick Intro to DGPR by Dr Sami Zahran GDPR Remediation Programme .. Intro by Dr. Sami Zahran 18