SlideShare una empresa de Scribd logo
1 de 33
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 0SM
withum.com
Presented by:
Anupam Goradia, CPA, CISA, CITP
Daniel Cohen-Dumani, Partner, Market Leader
Introduction to GDPR:
WEBINAR
What It Is, How It Will Affect Your
Business and How to Stay
Compliant
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 1SM
About Daniel
Daniel Cohen-Dumani
@dcohendumani
dcohendumani@withum.com
Partner,
Market
Leader
15+ years of Digital Transformation
Expertise with Office 365, SharePoint and
Dynamics
SharePoint Visionary
Interests: Productivity in the
Modern Workplace. Work 2.0
Started working with
SharePoint when nobody
could spell it
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 2SM
About Anupam
Anupam Goradia
agoradia@withum.com
CPA, CISA,
CITP, Senior
Manager
15+ years of public accounting experience,
plus extensive experience in internal audit,
risk management and internal control related
consulting services.
Member of Withum’s
Cybersecurity team as well
as the Governance, Risk and
Compliance Services team.
Specializes in Construction,
Government, Not-for-Profit
and Education, and Real
Estate
BE IN A POSITION OF STRENGTH | withum.com
Agenda
Introduction: What Is GDPR?
How Does GDPR Impact Your Business?
What Can You Do to Stay Compliant?
The Role of Microsoft Technology in Ensuring Compliance
Q&A
digital.withum.com
BE IN A POSITION OF STRENGTH | withum.com
Providing clarity and consistency for the protection
of personal data
Enhanced personal privacy rights
Increased duty for protecting data
Mandatory breach reporting
Significant penalties for non-compliance
The General Data Protection
Regulation (GDPR) imposes new
rules on organizations in the European
Union (EU) and those that offer goods and
services to people in the EU, or that collect
and analyze data tied to EU residents, no
matter where they are located.
Microsoft believes the GDPR is an important step forward for clarifying and enabling individual privacy rights
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 5SM
General Data Protection Regulation
(GDPR)
A European Union regulation
It is about the protection of privacy and
data of EU “data subjects”
Has implications beyond EU
Organization for Economic Co-
operation and Development (OECD)
Non-compliance can have penalties
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 6SM
Poll Number 1:
 Do you currently have EU exposure that would require GDPR compliance?
 Yes
 No
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 7SM
History of Privacy Regulation in Europe
OECD documented
first guidelines in
1980
Data protection
directive was
issued in 1995
OCED revises
guidelines in 2013
EU Parliament
approves GDPR in
2016
Data protection
and its regulation
is a global
phenomenon
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 8SM
Implications Beyond EU
GDPR affects your organization if:
 Your organization offers goods or services to
EU data subjects or monitors their behavior
 Processes and holds “personal data” of data
subjects residing in EU (regardless of
organization’s location)
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 9SM
Penalties for
Non-
Compliance
Up to 4% of annual
global turnover or
20 Million Euros
(maximum).
Which businesses can be subject to
penalty?
• If your organization offers goods or
services EU data subjects or monitors
their behavior
• Processing and holding of “personal
data” of data subjects residing in EU
(regardless of organization’s location)
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 10SM
Personal Data
Includes
• Name
• An identification number
• Location data
• Computer IP address
• An online identifier to one more factors
specific to the:
 Physical, physiological, genetic,
mental, economic, culture or social
identify of that natural person
Data Subjects
Identified or Identifiable natural person
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 11SM
Poll Number 2:
Which of the following is false:
1) GDPR extends to paper based records
2) GDPR stands for Gross Domestic Product Regulation
3) GDPR will not impact UK due to Brexit
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 12SM
Right to
Access
Data subjects have a right
to obtain a free copy of
their personal data in an
electronic format.
Data subjects can request
information on where the
data is being processed
and for what purposes.
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 13SM
Right to be
Forgotten
Also known as right of erasure
Data subjects can request to:
• Erase his/her personal data
• Cease further dissemination of the data
• Have third parties halt processing of data
Discretion in cases when there is
public interest in the availability
of data
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 14SM
Data
Portability
and
Conditions
of Consent
• Data subjects have the right to
transmit data to another data
controller
Data Portability
• Data subjects have to give their
informed consent; consent
cannot be assumed
Conditions of Consent
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 15SM
Privacy by
Design
Inclusion of data protection from the
onset of the designing of systems
Requires organizations to ‘implement
appropriate technical and
organizational measures….in an
effective way…in order to meet the
requirements of this Regulation and
protect rights of data subjects’.
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 16SM
Other
Requirement
s
Breach notifications
•Within 72 hours of
becoming aware of the
breach*
Data Controller and
Data Processor
•Processor has to meet
compliance
Data Protection
Officer “DPO”
•Most companies would be
required to designate a
DPO
* According to a recent report from FireEye, it takes an average of 146 days to discover a breach
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 17SM
Summary of Key Changes for GDPR
Personal
Privacy
Controls and
Notifications
Transparent
Policies
IT and Training
Organizations will need to:
• Train privacy personnel &
employees
• Audit and update data
policies
• Employ a Data Protection
Officer (if required)
• Create & manage
compliant vendor
contracts
Organizations will need to:
• Protect personal data using
appropriate security
• Notify authorities of
personal data breaches
• Obtain appropriate consents
for processing data
• Keep records detailing data
processing
Individuals have the right to:
• Access their personal
data
• Correct errors in their
personal data
• Erase their personal data
• Object to processing of
their personal data
• Export personal data
Organizations are required to:
• Provide clear notice of
data collection
• Outline processing
purposes and use cases
• Define data retention and
deletion policies
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 18SM
Poll Number 3:
GDPR may not apply to the following:
1. A local dollar store
2. A company providing online education across borders
3. A data center hosting payroll records of EU citizens located in Virginia, United
States
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 19SM
Where Do We
Stand on GDPR
Compliance?
 Over half of US multinationals say GDPR is their
top data protection priority
 While 24% of respondents plan to spend under
$1 million for GDPR preparations, 68% said they
will invest between $1 million and $10 million.
Nine percent (9%) expect to spend over $10
million to address GDPR obligations
 23% of surveyed respondents have not started
GDPR compliance
 71% have begun GDPR preparation
Source : December 2016 PwC Survey
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 20SM
What Needs to be Done:
Data
Discovery
1
Information
Security
Enhancement
2
Third-Party
Risk
Management
3
GDPR Gap
Assessment
4
Remediation
5
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 21SM
Let’s Talk Small Business…
Do I Even Have to be
Compliant?
 Now?
 Maybe now?
 In the future?
 Never?
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 22SM
Regardless of the GDPR Compliance Requirements…
Data protection should be your number one priority!
These basics should always be in place at your organization:
• IT Policies and Procedures
• Cybersecurity Risk Assessment
• IT Audits
• Penetration Testing
Available framework - NIST Small Business IT Framework
GDPR is all about data protection!
Data protection should be every organization’s top priority!
BE IN A POSITION OF STRENGTH | withum.com
Preparing for the GDPR
Leverage guidance
from experts
Simplify your
privacy journey
GDPR
Compliance
GDPR
Compliance
GDPR
Compliance
Uncover risk &
take action
BE IN A POSITION OF STRENGTH | withum.com
How Do I Get Started?
Identify what personal data you have and
where it resides
Discover1
Govern how personal data is used
and accessed
Manage2
Establish security controls to prevent, detect,
and respond to vulnerabilities & data breaches
Protect3
Keep required documentation, manage data
requests and breach notifications
Report4
BE IN A POSITION OF STRENGTH | withum.com
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 26SM
Poll Number 4:
Do you currently have Office 365?
1. Yes
2. No
3. Not sure
BE IN A POSITION OF STRENGTH | withum.com
Discover:
Identify what personal data you have and
where it resides
In-scope:
•
•
•
•
•
•
•
•
•
•
Inventory:
•
•
•
•
•
•
•
Microsoft Azure
Microsoft Azure Data Catalog
Enterprise Mobility + Security (EMS)
Microsoft Cloud App Security
Dynamics 365
Audit Data & User Activity
Reporting & Analytics
Office & Office 365
Data Loss Prevention
Advanced Data Governance
Office 365 eDiscovery
SQL Server and Azure SQL Database
SQL Query Language
Windows & Windows Server
Windows Search
Examples of Microsoft Solutions1
BE IN A POSITION OF STRENGTH | withum.com
2 Manage:
Data governance:
•
•
•
•
•
•
•
•
Data classification:
•
•
•
•
•
•
•
Microsoft Azure
Azure Active Directory
Azure Information Protection
Azure Role-Based Access Control (RBAC)
Enterprise Mobility + Security (EMS)
Azure Information Protection
Dynamics 365
Security Concepts
Office & Office 365
Advanced Data Governance
Journaling (Exchange Online)
Windows & Windows Server
Microsoft Data Classification Toolkit
Examples of Microsoft Solutions
BE IN A POSITION OF STRENGTH | withum.com
3 Protect:
Preventing data
attacks:
•
•
•
•
•
•
•
•
Detecting &
responding to
breaches:
•
•
•
•
•
•
Microsoft Azure
Azure Key Vault
Azure Security Center
Azure Storage Services Encryption
Enterprise Mobility + Security (EMS)
Azure Active Directory Premium
Microsoft Intune
Office & Office 365
Advanced Threat Protection
Threat Intelligence
SQL Server and Azure SQL Database
Transparent data encryption
Always Encrypted
Windows & Windows Server
Windows Defender Advanced Threat Protection
Windows Hello
Device Guard
Examples of Microsoft Solutions
BE IN A POSITION OF STRENGTH | withum.com
4
Record-keeping:
•
•
•
•
•
Reporting tools:
•
•
•
•
•
•
Microsoft Trust Center
Service Trust Portal
Microsoft Azure
Azure Auditing & Logging
Azure Data Lake
Azure Monitor
Enterprise Mobility + Security (EMS)
Azure Information Protection
Dynamics 365
Reporting & Analytics
Office & Office 365
Service Assurance
Office 365 Audit Logs
Customer Lockbox
Windows & Windows Server
Windows Defender Advanced Threat Protection
Report: Examples of Microsoft Solutions
WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 31SM
Q&A
BE IN A POSITION OF STRENGTH | withum.com
NEXT STEPS
To learn more about GDPR visit digital.withum.com
Are You Prepared to Meet GDPR Compliance?
Take advantage of our no obligation consultation.
We’ll help you make sure you’re on the right path to being
prepared.
Schedule a Free Consultation
Click Here

Más contenido relacionado

La actualidad más candente

GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersSpain-Holiday.com
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
GDPR - General Data Protection Regulation
GDPR - General Data Protection RegulationGDPR - General Data Protection Regulation
GDPR - General Data Protection RegulationZero Point Development
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR ComplianceDATAVERSITY
 
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015Constantine Karbaliotis
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...Browne Jacobson LLP
 
GDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentGDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentAllen Woods
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinWhitmeyerTuffin
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for DummiesAtif Ghauri
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security:  Risk Management and AvoidancePrivacy and Data Security:  Risk Management and Avoidance
Privacy and Data Security: Risk Management and AvoidanceAmy Purcell
 
*Webinar* CCPA: Get Your Business Ready
*Webinar* CCPA: Get Your Business Ready*Webinar* CCPA: Get Your Business Ready
*Webinar* CCPA: Get Your Business ReadyMoEngage Inc.
 

La actualidad más candente (18)

Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR - General Data Protection Regulation
GDPR - General Data Protection RegulationGDPR - General Data Protection Regulation
GDPR - General Data Protection Regulation
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...The Information Commissioner calls - what to expect and how to react, May 201...
The Information Commissioner calls - what to expect and how to react, May 201...
 
GDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentGDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal Environment
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security:  Risk Management and AvoidancePrivacy and Data Security:  Risk Management and Avoidance
Privacy and Data Security: Risk Management and Avoidance
 
*Webinar* CCPA: Get Your Business Ready
*Webinar* CCPA: Get Your Business Ready*Webinar* CCPA: Get Your Business Ready
*Webinar* CCPA: Get Your Business Ready
 

Similar a Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business

Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018Human Capital Department
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowSymantec
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeIBB Law
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRRichard Veryard
 
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...Symantec
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteSilverTech
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findwise
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 septRachel Aldighieri
 

Similar a Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business (20)

GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t know
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPRDigital Disruption and Consumer Trust - Resolving the Challenge of GDPR
Digital Disruption and Consumer Trust - Resolving the Challenge of GDPR
 
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
How the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your WebsiteHow the EU-GDPR May Affect Your Website
How the EU-GDPR May Affect Your Website
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
Scotland legal update 25 sept
Scotland legal update   25 septScotland legal update   25 sept
Scotland legal update 25 sept
 

Más de WithumSmith+Brown, formerly Portal Solutions

Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...
Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...
Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...WithumSmith+Brown, formerly Portal Solutions
 

Más de WithumSmith+Brown, formerly Portal Solutions (20)

Webinar: Stay Productive at Home with Microsoft 365
Webinar: Stay Productive at Home with Microsoft 365Webinar: Stay Productive at Home with Microsoft 365
Webinar: Stay Productive at Home with Microsoft 365
 
Webinar: Microsoft 365 - Your Gateway to Data Loss Prevention
Webinar: Microsoft 365 - Your Gateway to Data Loss PreventionWebinar: Microsoft 365 - Your Gateway to Data Loss Prevention
Webinar: Microsoft 365 - Your Gateway to Data Loss Prevention
 
Webinar: Adding Intelligence to Process Automation
Webinar: Adding Intelligence to Process AutomationWebinar: Adding Intelligence to Process Automation
Webinar: Adding Intelligence to Process Automation
 
Webinar: Top 8 Must Haves for Your Office 365 Intranet
Webinar: Top 8 Must Haves for Your Office 365 Intranet Webinar: Top 8 Must Haves for Your Office 365 Intranet
Webinar: Top 8 Must Haves for Your Office 365 Intranet
 
Webinar: Jumpstart to Microsoft Teams
Webinar: Jumpstart to Microsoft Teams Webinar: Jumpstart to Microsoft Teams
Webinar: Jumpstart to Microsoft Teams
 
Webinar: Is Microsoft Teams Turned On, But Not Rolled Out? Reining in the Wi...
Webinar: Is Microsoft Teams Turned On, But Not Rolled Out?  Reining in the Wi...Webinar: Is Microsoft Teams Turned On, But Not Rolled Out?  Reining in the Wi...
Webinar: Is Microsoft Teams Turned On, But Not Rolled Out? Reining in the Wi...
 
Webinar: Microsoft Teams: Your Light Weight Project Management Toolkit
Webinar: Microsoft Teams: Your Light Weight Project Management ToolkitWebinar: Microsoft Teams: Your Light Weight Project Management Toolkit
Webinar: Microsoft Teams: Your Light Weight Project Management Toolkit
 
Webinar: Video Conferencing Made Easy With Microsoft Teams, Skype for Busines...
Webinar: Video Conferencing Made Easy With Microsoft Teams, Skype for Busines...Webinar: Video Conferencing Made Easy With Microsoft Teams, Skype for Busines...
Webinar: Video Conferencing Made Easy With Microsoft Teams, Skype for Busines...
 
Microsoft ignite 2018 key takeaways - webinar
Microsoft ignite 2018   key takeaways - webinarMicrosoft ignite 2018   key takeaways - webinar
Microsoft ignite 2018 key takeaways - webinar
 
Webinar: Office 365 Turns 5! Does Modern Equal Mature?
Webinar: Office 365 Turns 5! Does Modern Equal Mature?Webinar: Office 365 Turns 5! Does Modern Equal Mature?
Webinar: Office 365 Turns 5! Does Modern Equal Mature?
 
Webinar: Workforce Modernization - Embrace Change without Compromising
Webinar: Workforce Modernization - Embrace Change without CompromisingWebinar: Workforce Modernization - Embrace Change without Compromising
Webinar: Workforce Modernization - Embrace Change without Compromising
 
Webinar: Building Your Document Management Strategy for Office 365
Webinar: Building Your Document Management Strategy for Office 365Webinar: Building Your Document Management Strategy for Office 365
Webinar: Building Your Document Management Strategy for Office 365
 
Webinar: Benefits of an ERP Solution for Wholesale Distributors
Webinar:  Benefits of an ERP Solution for Wholesale DistributorsWebinar:  Benefits of an ERP Solution for Wholesale Distributors
Webinar: Benefits of an ERP Solution for Wholesale Distributors
 
Webinar: ERP - When Paying Too Little Can Cost Too Much
Webinar: ERP - When Paying Too Little Can Cost Too MuchWebinar: ERP - When Paying Too Little Can Cost Too Much
Webinar: ERP - When Paying Too Little Can Cost Too Much
 
Webinar: Breaking Down Barriers to Achieve Sustainable Growth
Webinar: Breaking Down Barriers to Achieve Sustainable GrowthWebinar: Breaking Down Barriers to Achieve Sustainable Growth
Webinar: Breaking Down Barriers to Achieve Sustainable Growth
 
Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...
Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...
Webinar: Office 365 & Knowledge Management— Creating A Strategy For The Enter...
 
[Webinar] Understanding Microsoft Teams: What You Need to Know
[Webinar] Understanding Microsoft Teams: What You Need to Know[Webinar] Understanding Microsoft Teams: What You Need to Know
[Webinar] Understanding Microsoft Teams: What You Need to Know
 
Webinar: Digital Transformation for Healthcare
Webinar: Digital Transformation for HealthcareWebinar: Digital Transformation for Healthcare
Webinar: Digital Transformation for Healthcare
 
Webinar: What's New with SharePoint and OneDrive
Webinar: What's New with SharePoint and OneDriveWebinar: What's New with SharePoint and OneDrive
Webinar: What's New with SharePoint and OneDrive
 
Creating a Game Plan for Your Digital Transformation
Creating a Game Plan for Your Digital TransformationCreating a Game Plan for Your Digital Transformation
Creating a Game Plan for Your Digital Transformation
 

Último

Decarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityDecarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityIES VE
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Farhan Tariq
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...AliaaTarek5
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPathCommunity
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rick Flair
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfMounikaPolabathina
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Mark Goldstein
 
Manual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance AuditManual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance AuditSkynet Technologies
 
Sample pptx for embedding into website for demo
Sample pptx for embedding into website for demoSample pptx for embedding into website for demo
Sample pptx for embedding into website for demoHarshalMandlekar2
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 

Último (20)

Decarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityDecarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a reality
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to Hero
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...Rise of the Machines: Known As Drones...
Rise of the Machines: Known As Drones...
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdf
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
 
Manual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance AuditManual 508 Accessibility Compliance Audit
Manual 508 Accessibility Compliance Audit
 
Sample pptx for embedding into website for demo
Sample pptx for embedding into website for demoSample pptx for embedding into website for demo
Sample pptx for embedding into website for demo
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 

Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business

  • 1. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 0SM withum.com Presented by: Anupam Goradia, CPA, CISA, CITP Daniel Cohen-Dumani, Partner, Market Leader Introduction to GDPR: WEBINAR What It Is, How It Will Affect Your Business and How to Stay Compliant
  • 2. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 1SM About Daniel Daniel Cohen-Dumani @dcohendumani dcohendumani@withum.com Partner, Market Leader 15+ years of Digital Transformation Expertise with Office 365, SharePoint and Dynamics SharePoint Visionary Interests: Productivity in the Modern Workplace. Work 2.0 Started working with SharePoint when nobody could spell it
  • 3. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 2SM About Anupam Anupam Goradia agoradia@withum.com CPA, CISA, CITP, Senior Manager 15+ years of public accounting experience, plus extensive experience in internal audit, risk management and internal control related consulting services. Member of Withum’s Cybersecurity team as well as the Governance, Risk and Compliance Services team. Specializes in Construction, Government, Not-for-Profit and Education, and Real Estate
  • 4. BE IN A POSITION OF STRENGTH | withum.com Agenda Introduction: What Is GDPR? How Does GDPR Impact Your Business? What Can You Do to Stay Compliant? The Role of Microsoft Technology in Ensuring Compliance Q&A digital.withum.com
  • 5. BE IN A POSITION OF STRENGTH | withum.com Providing clarity and consistency for the protection of personal data Enhanced personal privacy rights Increased duty for protecting data Mandatory breach reporting Significant penalties for non-compliance The General Data Protection Regulation (GDPR) imposes new rules on organizations in the European Union (EU) and those that offer goods and services to people in the EU, or that collect and analyze data tied to EU residents, no matter where they are located. Microsoft believes the GDPR is an important step forward for clarifying and enabling individual privacy rights
  • 6. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 5SM General Data Protection Regulation (GDPR) A European Union regulation It is about the protection of privacy and data of EU “data subjects” Has implications beyond EU Organization for Economic Co- operation and Development (OECD) Non-compliance can have penalties
  • 7. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 6SM Poll Number 1:  Do you currently have EU exposure that would require GDPR compliance?  Yes  No
  • 8. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 7SM History of Privacy Regulation in Europe OECD documented first guidelines in 1980 Data protection directive was issued in 1995 OCED revises guidelines in 2013 EU Parliament approves GDPR in 2016 Data protection and its regulation is a global phenomenon
  • 9. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 8SM Implications Beyond EU GDPR affects your organization if:  Your organization offers goods or services to EU data subjects or monitors their behavior  Processes and holds “personal data” of data subjects residing in EU (regardless of organization’s location)
  • 10. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 9SM Penalties for Non- Compliance Up to 4% of annual global turnover or 20 Million Euros (maximum). Which businesses can be subject to penalty? • If your organization offers goods or services EU data subjects or monitors their behavior • Processing and holding of “personal data” of data subjects residing in EU (regardless of organization’s location)
  • 11. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 10SM Personal Data Includes • Name • An identification number • Location data • Computer IP address • An online identifier to one more factors specific to the:  Physical, physiological, genetic, mental, economic, culture or social identify of that natural person Data Subjects Identified or Identifiable natural person
  • 12. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 11SM Poll Number 2: Which of the following is false: 1) GDPR extends to paper based records 2) GDPR stands for Gross Domestic Product Regulation 3) GDPR will not impact UK due to Brexit
  • 13. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 12SM Right to Access Data subjects have a right to obtain a free copy of their personal data in an electronic format. Data subjects can request information on where the data is being processed and for what purposes.
  • 14. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 13SM Right to be Forgotten Also known as right of erasure Data subjects can request to: • Erase his/her personal data • Cease further dissemination of the data • Have third parties halt processing of data Discretion in cases when there is public interest in the availability of data
  • 15. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 14SM Data Portability and Conditions of Consent • Data subjects have the right to transmit data to another data controller Data Portability • Data subjects have to give their informed consent; consent cannot be assumed Conditions of Consent
  • 16. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 15SM Privacy by Design Inclusion of data protection from the onset of the designing of systems Requires organizations to ‘implement appropriate technical and organizational measures….in an effective way…in order to meet the requirements of this Regulation and protect rights of data subjects’.
  • 17. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 16SM Other Requirement s Breach notifications •Within 72 hours of becoming aware of the breach* Data Controller and Data Processor •Processor has to meet compliance Data Protection Officer “DPO” •Most companies would be required to designate a DPO * According to a recent report from FireEye, it takes an average of 146 days to discover a breach
  • 18. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 17SM Summary of Key Changes for GDPR Personal Privacy Controls and Notifications Transparent Policies IT and Training Organizations will need to: • Train privacy personnel & employees • Audit and update data policies • Employ a Data Protection Officer (if required) • Create & manage compliant vendor contracts Organizations will need to: • Protect personal data using appropriate security • Notify authorities of personal data breaches • Obtain appropriate consents for processing data • Keep records detailing data processing Individuals have the right to: • Access their personal data • Correct errors in their personal data • Erase their personal data • Object to processing of their personal data • Export personal data Organizations are required to: • Provide clear notice of data collection • Outline processing purposes and use cases • Define data retention and deletion policies
  • 19. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 18SM Poll Number 3: GDPR may not apply to the following: 1. A local dollar store 2. A company providing online education across borders 3. A data center hosting payroll records of EU citizens located in Virginia, United States
  • 20. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 19SM Where Do We Stand on GDPR Compliance?  Over half of US multinationals say GDPR is their top data protection priority  While 24% of respondents plan to spend under $1 million for GDPR preparations, 68% said they will invest between $1 million and $10 million. Nine percent (9%) expect to spend over $10 million to address GDPR obligations  23% of surveyed respondents have not started GDPR compliance  71% have begun GDPR preparation Source : December 2016 PwC Survey
  • 21. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 20SM What Needs to be Done: Data Discovery 1 Information Security Enhancement 2 Third-Party Risk Management 3 GDPR Gap Assessment 4 Remediation 5
  • 22. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 21SM Let’s Talk Small Business… Do I Even Have to be Compliant?  Now?  Maybe now?  In the future?  Never?
  • 23. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 22SM Regardless of the GDPR Compliance Requirements… Data protection should be your number one priority! These basics should always be in place at your organization: • IT Policies and Procedures • Cybersecurity Risk Assessment • IT Audits • Penetration Testing Available framework - NIST Small Business IT Framework GDPR is all about data protection! Data protection should be every organization’s top priority!
  • 24. BE IN A POSITION OF STRENGTH | withum.com Preparing for the GDPR Leverage guidance from experts Simplify your privacy journey GDPR Compliance GDPR Compliance GDPR Compliance Uncover risk & take action
  • 25. BE IN A POSITION OF STRENGTH | withum.com How Do I Get Started? Identify what personal data you have and where it resides Discover1 Govern how personal data is used and accessed Manage2 Establish security controls to prevent, detect, and respond to vulnerabilities & data breaches Protect3 Keep required documentation, manage data requests and breach notifications Report4
  • 26. BE IN A POSITION OF STRENGTH | withum.com
  • 27. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 26SM Poll Number 4: Do you currently have Office 365? 1. Yes 2. No 3. Not sure
  • 28. BE IN A POSITION OF STRENGTH | withum.com Discover: Identify what personal data you have and where it resides In-scope: • • • • • • • • • • Inventory: • • • • • • • Microsoft Azure Microsoft Azure Data Catalog Enterprise Mobility + Security (EMS) Microsoft Cloud App Security Dynamics 365 Audit Data & User Activity Reporting & Analytics Office & Office 365 Data Loss Prevention Advanced Data Governance Office 365 eDiscovery SQL Server and Azure SQL Database SQL Query Language Windows & Windows Server Windows Search Examples of Microsoft Solutions1
  • 29. BE IN A POSITION OF STRENGTH | withum.com 2 Manage: Data governance: • • • • • • • • Data classification: • • • • • • • Microsoft Azure Azure Active Directory Azure Information Protection Azure Role-Based Access Control (RBAC) Enterprise Mobility + Security (EMS) Azure Information Protection Dynamics 365 Security Concepts Office & Office 365 Advanced Data Governance Journaling (Exchange Online) Windows & Windows Server Microsoft Data Classification Toolkit Examples of Microsoft Solutions
  • 30. BE IN A POSITION OF STRENGTH | withum.com 3 Protect: Preventing data attacks: • • • • • • • • Detecting & responding to breaches: • • • • • • Microsoft Azure Azure Key Vault Azure Security Center Azure Storage Services Encryption Enterprise Mobility + Security (EMS) Azure Active Directory Premium Microsoft Intune Office & Office 365 Advanced Threat Protection Threat Intelligence SQL Server and Azure SQL Database Transparent data encryption Always Encrypted Windows & Windows Server Windows Defender Advanced Threat Protection Windows Hello Device Guard Examples of Microsoft Solutions
  • 31. BE IN A POSITION OF STRENGTH | withum.com 4 Record-keeping: • • • • • Reporting tools: • • • • • • Microsoft Trust Center Service Trust Portal Microsoft Azure Azure Auditing & Logging Azure Data Lake Azure Monitor Enterprise Mobility + Security (EMS) Azure Information Protection Dynamics 365 Reporting & Analytics Office & Office 365 Service Assurance Office 365 Audit Logs Customer Lockbox Windows & Windows Server Windows Defender Advanced Threat Protection Report: Examples of Microsoft Solutions
  • 32. WithumSmith+Brown, PC | BE IN A POSITION OF STRENGTH 31SM Q&A
  • 33. BE IN A POSITION OF STRENGTH | withum.com NEXT STEPS To learn more about GDPR visit digital.withum.com Are You Prepared to Meet GDPR Compliance? Take advantage of our no obligation consultation. We’ll help you make sure you’re on the right path to being prepared. Schedule a Free Consultation Click Here