SlideShare una empresa de Scribd logo
1 de 25
GDPR:
Are you Ready?
GDPR: Are you ready?
77%
#ReadyForGDPR 2
Feel ready for
compliance
Companies
aware of GDPR
34%
History of GDPR
#ReadyForGDPR 3
Post WWII, concerns about protection
of human rights.
1950, EU Convention on Human
Rights (ECHR) introduces privacy.
1981, EU Treaty 108
– Eight principles for protecting personal data
Convention for the Protection of Individuals with regard to Automatic
Processing of Personal Data
– Different Member States implemented their own laws to reflect this.
1998, all Member States transpose into law (e.g. UK’s DPA1998):
– Inconsistent protection of individual rights,
– Uneven organisational playing field.
2016, EU GDPR approved, becomes law
two years from publication.
1998, Human Rights Act (HRA 1998) – Article 8 ‘right to privacy’.
90% of the worlds data was created in the past 2 years
1950 1981 1998 2016
#ReadyForGDPR 4
Deadline:
May 25th 2018
A few basic definitions
EU Directive is a legal act of the European Union, which requires member states to achieve a
particular result without dictating the means of achieving that result. It can be distinguished from
Regulations which are self-executing and do not require any implementing measures. The Directive
leaves member states with a certain amount of leeway as to the exact rules to be adopted.
Personal data
“any information relating to an identifiable person who can be directly or indirectly
identified in particular by reference to an identifier”
Special categories of personal data specifically including genetic and biometric data when
processed to uniquely identify an individual – used to known as “sensitive data”.
#ReadyForGDPR 5
Processor vs Controller
#ReadyForGDPR 6
Data
Subject.
Data
Processor.
Sub-Processor.
Sub-Processor.
Data
Controller.
Data
Processor.
What does GDPR cover?
#ReadyForGDPR 7
Personal Rights
The right to be informed.
The right of access.
The right to rectification.
The right to erasure.
The right to restrict processing.
The right to data portability.
The right to object.
Rights in relation to automated
decision making and profiling.
Boundaries &
Scope
Details the scope of what is covered
by GDPR.
Details the geographical boundaries
of GDPR
Responsibilities
Outlines the responsibilities of
both Controllers & Processors.
#ReadyForGDPR 8
What does GDPR mean
for your business?
Key areas.
#ReadyForGDPR 9
Responsibility and
accountability
Consent
Pseudonymization
Data breaches Right to erase – “The
right to be forgotten”
Data portability
Records of
processing
activities
Accountability
#ReadyForGDPR 10
Article 5: Principles – personal data shall be:
1 Processed lawfully, fairly and in a transparent manner
2 Collected for specified, explicit and legitimate purposes
3 Adequate, relevant and limited to what is necessary
4 Accurate and, where necessary, kept up to date
5 Retained only for as long as necessary
6 Processed in an appropriate manner to maintain security
Accountability
Consent
#ReadyForGDPR 11
Unbundled
Should be separate from other T&CS
need to include an example e.g.
purchase can’t be refused if consent
isn’t given.
Active opt-in
Pre-ticked boxes are no
longer valid.
Named
3rd Parties listed.
Freely given
Not pressured into it.
Documented
List of when consent was given.
Easy to withdraw
As easy to withdraw as it is to give.
Subject Rights
#ReadyForGDPR 12
Right to be
forgotten.
Right to access.
Right to
rectification.
Data breaches
#ReadyForGDPR 13
Prepare
• Stop it before it happens
Protect
• Identify personal data
• Encrypt
• Enable only right people to access
• Patch systems, install AV and
anti-malware protection
Detect
• Evaluate existing technologies
• Identify vulnerabilities
• Monitor
• Test
Respond
• Mitigate the impact
• Report it
Data portability
The data subject shall have the right to receive the
personal data concerning him or her, which he or she
has provided to a controller, in a structured,
commonly used and machine-readable format and
have the right to transmit those data to another
controller without hindrance from the controller to
which the personal data have been provided...
#ReadyForGDPR 14
– EU GDPR Chapter 3, Article 20 &1.
What if you don’t comply?
• Fines and penalties
• Four per cent of your global annual turnover or €20m is
a large price to pay for direct breaches of the GDPR
principles, but even a minor breach is likely to cost you
2% or €10m at the bare minimum
• Legal action
• As long as businesses can demonstrate a sound and
practicable intent to enforce data security practices,
they should not be fearful of new data protection
regulations and European Union (EU)/ICO mega fines
• Keep working towards compliance once the deadline
has passed
#ReadyForGDPR 15
Checklist.
#ReadyForGDPR 16
Preparation check-list
 Conduct an audit of what data you hold
and where
 Privacy information and policies
 Processes for data breaches
 Review consent process
 Data Protection Officer
 Employee Data
#ReadyForGDPR 17
Brexit
• Life after Brexit – Do we care?
• What is adequacy assessment and does
it help?
• Binding contractual agreements
#ReadyForGDPR 18
DPB (Data Protection Bill)
• The existing UK data protection laws have become increasingly
unwieldy, having been first introduced in 1998 – 10 years before
Apple’s first smartphone was released.
• The DPB (Data Protection Bill) is the UK’s answer to the GDPR,
evolving the country’s existing data protection laws for the 21st
century with the aim of ensuring uninterrupted data flows between
the UK and EU after Brexit.
#ReadyForGDPR 19
3 Misconceptions of GDPR.
#ReadyForGDPR 20
Misconceptions of GDPR
#ReadyForGDPR 21
GDPR only affects those in the EU.
• European approach
• Privacy and data protection are fundamental human rights
• Not tied to citizenship or nationality
• One overarching law for all member states
Misconceptions of GDPR
• There’s also a misconception among businesses that when GDPR is
introduced there will be a grace period, but the reality is that
organisations need to be preparing now.
• 25 May 2018 is when the General Data Protection Regulation (GDPR)
comes into effect; the on-boarding period started two years ago in May
2016, and it has been on the horizon for three years
• If you read into GDPR, it essentially builds on data privacy and security
principles that organisations should already be abiding by – the Data
Protection Act has been in force since 1998, after all
#ReadyForGDPR 22
There will be a grace period.
Misconceptions of GDPR
• Comply with GDPR to make regulators but also customers happy
• Improved understanding of customer data lineage
• Collaboration across stakeholders
• Sharing consent with partners
• Improved customer experience
• GDPR competitive differentiation
#ReadyForGDPR 23
It will be much harder to
communicate with customers
and clients.
This will make your organisation trusted and authentic, inspiring
transparent relationships with your customers.
Put data protection at the
heart of your brand.
#ReadyForGDPR 24
www.engagehub.com

Más contenido relacionado

La actualidad más candente

EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection RegulationSabrina Kirrane
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownAgile PR
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017isc2-hellenic
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)Huub de Jong
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinWhitmeyerTuffin
 
Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Dione McBride, CISSP, CIPP/E
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationGhostery, Inc.
 

La actualidad más candente (20)

EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here20170323 are you ready the new gdpr is here
20170323 are you ready the new gdpr is here
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017GDPR Cyber Insurance 11/1/2017
GDPR Cyber Insurance 11/1/2017
 
GDPR 101
GDPR 101 GDPR 101
GDPR 101
 
MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)MindMap AVG Louwers Advocaten V 4.0 (EN)
MindMap AVG Louwers Advocaten V 4.0 (EN)
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 
Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar2016 11-17-gdpr-integro-webinar
2016 11-17-gdpr-integro-webinar
 

Similar a GDPR: Are you Ready?

GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookPlr-Printables
 
The Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsThe Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsHubilo
 
All you need to know about GDPR
All you need to know about GDPRAll you need to know about GDPR
All you need to know about GDPRHubilo
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guideAngad Dayal
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?VILT
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyKate Chan
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisAngad Dayal
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanEquiGov Institute
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRCase IQ
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingPromptCloud
 

Similar a GDPR: Are you Ready? (20)

GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e book
 
The Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsThe Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event Professionals
 
All you need to know about GDPR
All you need to know about GDPRAll you need to know about GDPR
All you need to know about GDPR
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
Fasten Your Belts for #GDPR
Fasten Your Belts for #GDPRFasten Your Belts for #GDPR
Fasten Your Belts for #GDPR
 
Fasten Your Belts for GDPR
Fasten Your Belts for GDPRFasten Your Belts for GDPR
Fasten Your Belts for GDPR
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with Varonis
 
GDPR
GDPRGDPR
GDPR
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and Processing
 

Último

Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon investment
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...lizamodels9
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Falcon Invoice Discounting
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876dlhescort
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...amitlee9823
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...amitlee9823
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizharallensay1
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Centuryrwgiffor
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 MonthsIndeedSEO
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangaloreamitlee9823
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...lizamodels9
 

Último (20)

Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business Potential
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 

GDPR: Are you Ready?

  • 2. GDPR: Are you ready? 77% #ReadyForGDPR 2 Feel ready for compliance Companies aware of GDPR 34%
  • 3. History of GDPR #ReadyForGDPR 3 Post WWII, concerns about protection of human rights. 1950, EU Convention on Human Rights (ECHR) introduces privacy. 1981, EU Treaty 108 – Eight principles for protecting personal data Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data – Different Member States implemented their own laws to reflect this. 1998, all Member States transpose into law (e.g. UK’s DPA1998): – Inconsistent protection of individual rights, – Uneven organisational playing field. 2016, EU GDPR approved, becomes law two years from publication. 1998, Human Rights Act (HRA 1998) – Article 8 ‘right to privacy’. 90% of the worlds data was created in the past 2 years 1950 1981 1998 2016
  • 5. A few basic definitions EU Directive is a legal act of the European Union, which requires member states to achieve a particular result without dictating the means of achieving that result. It can be distinguished from Regulations which are self-executing and do not require any implementing measures. The Directive leaves member states with a certain amount of leeway as to the exact rules to be adopted. Personal data “any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier” Special categories of personal data specifically including genetic and biometric data when processed to uniquely identify an individual – used to known as “sensitive data”. #ReadyForGDPR 5
  • 6. Processor vs Controller #ReadyForGDPR 6 Data Subject. Data Processor. Sub-Processor. Sub-Processor. Data Controller. Data Processor.
  • 7. What does GDPR cover? #ReadyForGDPR 7 Personal Rights The right to be informed. The right of access. The right to rectification. The right to erasure. The right to restrict processing. The right to data portability. The right to object. Rights in relation to automated decision making and profiling. Boundaries & Scope Details the scope of what is covered by GDPR. Details the geographical boundaries of GDPR Responsibilities Outlines the responsibilities of both Controllers & Processors.
  • 8. #ReadyForGDPR 8 What does GDPR mean for your business?
  • 9. Key areas. #ReadyForGDPR 9 Responsibility and accountability Consent Pseudonymization Data breaches Right to erase – “The right to be forgotten” Data portability Records of processing activities
  • 10. Accountability #ReadyForGDPR 10 Article 5: Principles – personal data shall be: 1 Processed lawfully, fairly and in a transparent manner 2 Collected for specified, explicit and legitimate purposes 3 Adequate, relevant and limited to what is necessary 4 Accurate and, where necessary, kept up to date 5 Retained only for as long as necessary 6 Processed in an appropriate manner to maintain security Accountability
  • 11. Consent #ReadyForGDPR 11 Unbundled Should be separate from other T&CS need to include an example e.g. purchase can’t be refused if consent isn’t given. Active opt-in Pre-ticked boxes are no longer valid. Named 3rd Parties listed. Freely given Not pressured into it. Documented List of when consent was given. Easy to withdraw As easy to withdraw as it is to give.
  • 12. Subject Rights #ReadyForGDPR 12 Right to be forgotten. Right to access. Right to rectification.
  • 13. Data breaches #ReadyForGDPR 13 Prepare • Stop it before it happens Protect • Identify personal data • Encrypt • Enable only right people to access • Patch systems, install AV and anti-malware protection Detect • Evaluate existing technologies • Identify vulnerabilities • Monitor • Test Respond • Mitigate the impact • Report it
  • 14. Data portability The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided... #ReadyForGDPR 14 – EU GDPR Chapter 3, Article 20 &1.
  • 15. What if you don’t comply? • Fines and penalties • Four per cent of your global annual turnover or €20m is a large price to pay for direct breaches of the GDPR principles, but even a minor breach is likely to cost you 2% or €10m at the bare minimum • Legal action • As long as businesses can demonstrate a sound and practicable intent to enforce data security practices, they should not be fearful of new data protection regulations and European Union (EU)/ICO mega fines • Keep working towards compliance once the deadline has passed #ReadyForGDPR 15
  • 17. Preparation check-list  Conduct an audit of what data you hold and where  Privacy information and policies  Processes for data breaches  Review consent process  Data Protection Officer  Employee Data #ReadyForGDPR 17
  • 18. Brexit • Life after Brexit – Do we care? • What is adequacy assessment and does it help? • Binding contractual agreements #ReadyForGDPR 18
  • 19. DPB (Data Protection Bill) • The existing UK data protection laws have become increasingly unwieldy, having been first introduced in 1998 – 10 years before Apple’s first smartphone was released. • The DPB (Data Protection Bill) is the UK’s answer to the GDPR, evolving the country’s existing data protection laws for the 21st century with the aim of ensuring uninterrupted data flows between the UK and EU after Brexit. #ReadyForGDPR 19
  • 20. 3 Misconceptions of GDPR. #ReadyForGDPR 20
  • 21. Misconceptions of GDPR #ReadyForGDPR 21 GDPR only affects those in the EU. • European approach • Privacy and data protection are fundamental human rights • Not tied to citizenship or nationality • One overarching law for all member states
  • 22. Misconceptions of GDPR • There’s also a misconception among businesses that when GDPR is introduced there will be a grace period, but the reality is that organisations need to be preparing now. • 25 May 2018 is when the General Data Protection Regulation (GDPR) comes into effect; the on-boarding period started two years ago in May 2016, and it has been on the horizon for three years • If you read into GDPR, it essentially builds on data privacy and security principles that organisations should already be abiding by – the Data Protection Act has been in force since 1998, after all #ReadyForGDPR 22 There will be a grace period.
  • 23. Misconceptions of GDPR • Comply with GDPR to make regulators but also customers happy • Improved understanding of customer data lineage • Collaboration across stakeholders • Sharing consent with partners • Improved customer experience • GDPR competitive differentiation #ReadyForGDPR 23 It will be much harder to communicate with customers and clients.
  • 24. This will make your organisation trusted and authentic, inspiring transparent relationships with your customers. Put data protection at the heart of your brand. #ReadyForGDPR 24

Notas del editor

  1. http://www.information-age.com/5-eu-companies-ready-gdpr-compliance-alert-logic-123469223/ - varying compliance statistics. This comes from our own research Nigel to add Forrester article: Which sectors are most ready – finance being more vigiliant Gen to add notes from Blog
  2. 90% of the worlds data was created in the past 2 years:: http://www.deleteagency.com/news/the-impact-of-general-data-protection-regulations-gdpr-on-your-customer-marketing Create timeline reflecting and highlighting the key dates: 1950, 1981, 1998 and 2016 Time line effect design
  3. EU Regulation is a legal act of the European Union that becomes immediately enforceable as law in all member states simultaneously. EU Directive is a legal act of the European Union, which requires member states to achieve a particular result without dictating the means of achieving that result. It can be distinguished from regulations which are self-executing and do not require any implementing measures. The Directive leaves member states with a certain amount of leeway as to the exact rules to be adopted
  4. We can produce a diagram which explains this in more detail – processor vs controller : https://lh3.googleusercontent.com/Mg8TMJS7-qXeaMifQcJRN7fVdqnD0-KGsRHJ41Nqt_HW5oiWnhwZi_tMaMyZZyQU4XzJBcqvGduEjbFeHoIU-MntozztlD5p0HTJS00bZLW7-DIJKPGL9VhQ4T32gR-PotITXeLM Changes to Data controller and Data processor responsibilities Controller “determines the purposes and means of the processing of personal data”, while a processor is “any person who processes personal data on behalf of the controller (other than a person who is an employee of the controller)”. One of the major changes is that data processors have specific obligations under the GDPR – if a processor fails to report a data loss to their controller, then the processor can be subject to regulatory action from the commissioner, where that isn’t possible under the current Data Protection Act
  5. If you are a processor, the GDPR places specific legal obligations on you; for example, you are required to maintain records of personal data and processing activities. You will have legal liability if you are responsible for a breach. if you are a controller, you are not relieved of your obligations where a processor is involved – the GDPR places further obligations on you to ensure your contracts with processors comply with the GDPR. The GDPR applies to processing carried out by organisations operating within the EU. It also applies to organisations outside the EU that offer goods or services to individuals in the EU. Include icons per point
  6. Can we add icons for your business – engaging icons
  7. ----- Meeting Notes (29/01/18 12:35) ----- PECR cross reference covering up to. Consent can not be part of the offering. 6 x icons Example: It’s given by ticking a box, it should possible to un-tick the box. RECOMMENDED: Bring your entire database up to GDPR standards, it seems required.
  8. If you are a processor, the GDPR places specific legal obligations on you; for example, you are required to maintain records of personal data and processing activities. You will have legal liability if you are responsible for a breach. if you are a controller, you are not relieved of your obligations where a processor is involved – the GDPR places further obligations on you to ensure your contracts with processors comply with the GDPR. The GDPR applies to processing carried out by organisations operating within the EU. It also applies to organisations outside the EU that offer goods or services to individuals in the EU. Include icons per point
  9. Report must include likely consequences of the breach and the actions taken to mitigate impact on the data subjects Visually creative with 4 steps: Prepare, Protect, Detect, Respond
  10. Visually represent the importance of this slide – needs to stand out as a warning
  11. Ask questions?
  12. When the UK leaves the EU, it becomes what is known as a “third country”. According to Clause 31(7) of the DPB, this is “a country or territory other than a Member State”. If there is no deal in place, this could have massive repercussions for data sharing, as Clause 71(1) of the DPB states: “A company may not transfer data to a third country. For the UK to share data with its European partners, an “adequacy assessment” will be needed. This is not as easy as it sounds, as adequacy assessments normally take more than a year. Likewise, an adequacy assessment endorsement cannot be issued to an existing Member State, as being a member precludes the necessity of having an adequacy assessment in the first place. Should the UK leave the EU without a deal in place, EU organisations will need to have binding contractual arrangements in place every time they wish to share new information and data with their UK partners. Only once an adequacy assessment was in place could this be dispensed with.
  13. The DPB aims to reinforce data protection regulation for new technologies, while allowing people to have more control over their data. This will be no easy task, as – given the definitions used in the DPB – the UK will have more than 60,000,000 data subjects (a person who has data stored about them) and approximately 500,000 data controllers (companies or organisations which store data about data subjects). The UK Data Protection Bill is due to come into force this year, ahead of the EU General Data Protection Regulation in May 2018 The first draft of the Data Protection Bill (DPB) was released on 13 September 2017, following its second reading in the House of Lords. This bill is designed to bring the UK’s data protection laws in line with the European Union’s (EU) General Data Protection Regulation (GDPR). Despite the UK government having triggered Article 50 of the Lisbon Treaty, and being in negotiations regarding leaving the EU, the UK will still be classed as a Member State when the GDPR compliance deadline is reached on 25 May 2018. [may be removed in dry-run]
  14. Graphics to add – quote big and Have 1 as a big number. And title in big centred
  15. Same as point 1.
  16. Opportunities for your business – interactive diagram (3 x slides) By placing respect for privacy at the heart of brand proposition. Transforming the way it projects to customers, making every engagement human-centric. This will ascribe organisation as trusted and authentic, inspiring transparent relationships with their customers. Linked to next slide.
  17. Health theme – a ‘core brand value’ similar to our retail whitepaper infographic messaging - some image here would be good to represent this Have health theme image. Like an ad.