SlideShare a Scribd company logo
1 of 46
w: rencore.com | e: info@rencore.com | t: @rencoreab
Manage Customization Risk and
Save on Maintenance Costs!
Customization governance, transformation
and risk prevention for SharePoint & Office365
Understanding EU GDPR
from an Office 365 perspective
October 24th, 2017
rencore.com
Our Guest:
Erwin van Hunen
Microsoft MVP, MCM
SharePoint PnP Core Team
Product Owner - Transformation
Your Host:
Paolo Pialorsi
Microsoft MVP, MCSM
SharePoint PnP Core Team
Founder & CEO of PiaSys
rencore.com
Q&A
Please use the Q&A functionality in Zoom instead of
chat.
We will pick up some questions at the end and answer
the others in the follow-up email.
FAQ:
Recording of this webinar?
Yes, the session is recorded and you will get the
recording later today.
http://www.piasys.com/
Understanding EU GDPR from
an Office 365 perspective
Paolo Pialorsi - @PaoloPia
Senior Consultant – PiaSys.com
http://www.piasys.com/
Agenda
 Why GDPR compliancy matters?
 From an IT perspective
 Office 365 and GDPR
 GDPR Activity Hub
http://www.piasys.com/
Why GDPR compliancy matters?
http://www.piasys.com/
What is GDPR?
 GDPR = General Data Protection Regulation
 Regulation (EU) 2016/679
 It will go LIVE on May 25, 2018
 It’s a regulation not a directive
 Regulation: Immediately applicable and enforceable by law in all Member
States
 Directive: needs to be transposed into national law by Member States
 Scope: protection of data for all individuals in the EU
http://www.piasys.com/
I’m outside EU, does it matter for me?
 Yes it does!
 If you process, hold, store, manage personal data
of any EU resident …
 … you need to be compliant with GDPR!
 Regardless where you are and where your business is located!
http://www.piasys.com/
Common definitions
 Data Subject: an identified or identifiable natural person
 Personal Data: any information relating to a Data Subject
 Processing: any operation or set of operations which is performed on
Personal Data or on sets of Personal Data
http://www.piasys.com/
GDPR Roles
 Data Controller: the natural or legal person, public authority, agency
or other body which, alone or jointly with others, determines the
purposes and means of the processing of personal data
 Data Processor: a natural or legal person, public authority, agency or
other body which processes personal data on behalf of the controller
 Data Protection Officer: provides guidance on the implementation of
appropriate measures and on the demonstration of compliance
http://www.piasys.com/
Key changes under GDPR
Personal Privacy
•Individuals have the right to:
•Access their personal data
•Correct errors in their personal data
•Erase their personal data
•Object to processing of their personal data
•Export personal data
Controls and notifications
•Organizations will need to:
• Protect personal data using appropriate
security
• Notify authorities of personal data breaches
• Obtain appropriate consents for processing
data
• Keep records detailing data processing
Transparent policies
•Organizations are required to:
• Provide clear notice of data collection
• Outline processing purposes and use cases
• Define data retention and deletion policies
IT and training
•Organizations will need to:
• Train privacy personnel and employees
• Audit and update data policies
• Employ a Data Protection Officer (if required)
• Create and manage compliant vendor
contracts
http://www.piasys.com/
Some IT requirements
 You need to keep track of events like:
 Data Breaches
 Data Consent
 Data Consent Withdrawal
 Identity Risks/Theft
 Data Processing
 Data Archived
 You need to collect requests for:
 Data Access
 Data Correction
 Data Export
 Data Processing Objection
 Data Erase
http://www.piasys.com/
Just to make an example …
 As soon as the controller becomes aware that a personal data breach
has occurred, the controller should notify the personal data breach
to the supervisory authority without undue delay and, where feasible,
not later than 72 hours after having become aware of it
 A supervisor authority can be a data protection authority (DPA)
 Thus, you will need a workflow process for Data Breaches!
http://www.piasys.com/
Office 365 and GDPR
http://www.piasys.com/
In February 2017, Microsoft
announced that its cloud
services will comply with GDPR
by May 25, 2018
http://www.piasys.com/
Main capabilities of Office 365 for GDPR
compliancy
• Tooling
• Office 365 Secure Score
• Data Loss Prevention (DLP)
• Office 365 eDiscovery
• Customer Lockbox
• Monitoring & Logging
• Advanced Threat Protection
• Threat Intelligence
• Cloud App Security
• Office 365 Unified Audit Logs
• Governance
• Advanced Data Governance (ADG)
• SharePoint Online Site
Classification
• Reporting
• Security & Compliance Reports
• Risk & Compliance Dashboard
http://www.piasys.com/
Office 365 Secure Score
 Accessible to all admins
 Based on the services you are using
 Compares your services settings with a baseline provided by
Microsoft
 Gives you an “actions” queue to accomplish to improve your score
 Provides detailed instructions about what to do
 Whatever will be your score …
 … there is no guarantee that you will not be breached …
http://www.piasys.com/
Demo
Office 365 Secure Score
http://www.piasys.com/
Data Loss Prevention
 Enable you to identify sensitive/personal data as it travels through
Exchange Online, SharePoint Online, and OneDrive for Business
 You can use it to
 Identify sensitive information across many locations (SharePoint Online,
Exchange Online, OneDrive for Business)
 Prevent accidental sharing of such sensitive information
 Monitor and protect from sharing sensitive data inside client applications
 Excel 2016, Word 2016, PowerPoint 2016
 Help user stay compliant
 Collect data and view DLP reports about content matching policies
http://www.piasys.com/
Anatomy of DLP Policies
 Locations: SPO, EXO,OD4B
 Rules
 One or more for each policy
 Conditions and Actions
 Conditions
 Content: Classification
 Labels / Sensitive Information Types
 Context: inside/outside tenant
 Actions
 Restrict access to content
http://www.piasys.com/
http://www.piasys.com/
DLP Reporting
 Various reports available out of the box
 Top DLP policy matches for mail
 Top DLP rule matches for mail
 DLP policy matches by severity for mail
 DLP policy matches, overrides, and false positives for mail
http://www.piasys.com/
Demo
Data Loss Prevention (DLP)
http://www.piasys.com/
Office 365 eDiscovery
 In-place eDiscovery for investigating cases and search for related content
 Provides hold, analyze, and export capabilities
 Targets almost every content in your organization
 Email
 Documents
 Skype for Business conversations
 Teams data
 Etc.
 Advanced eDiscovery leverages
 Machine learning
 Predictive coding
 Text analytics
http://www.piasys.com/
Customer Lockbox
 Ensures that Microsoft engineer does not get access to the
customer’s content without customer’s explicit approval
 All access is obtained through a rigorous access control technology
 Administrators can approve or reject the request
 Customer Lockbox requests have a default lifetime of 12 hours
 You need Office 365 E5 or you have to buy the functionality
separately
http://www.piasys.com/
Demo
Customer Lockbox
http://www.piasys.com/
Advanced Threat Protection
 Cloud-based email filtering service
 Helps protect email against unknown, sophisticated malware attacks
 Main functionalities
 Anti-malware
 Safe links
 Safe attachments
 Spoof intelligence
 Quarantine
 Advanced anti-phishing capabilities
 DKIM (DomainKeys Identified Mail)
 Provides reach reporting and tracking
http://www.piasys.com/
Threat Intelligence
 Helps you proactively uncover and protect against advanced threats in Office 365
 Office 365 Threat Intelligence monitors signals from sources
 User activity
 Authentication
 Email
 Compromised PCs
 Security incidents
 Provides tools like
 Threat dashboard
 Threat explorer
 Incidents
 Threat Intelligence Feeds
 Integration with Windows Defender
http://www.piasys.com/
Cloud App Security
 AKA “Advanced Security Management”
 Gives you insights into suspicious activity in Office 365
 See how your organization's data in Office 365 is accessed and used
 Define policies that trigger alerts for atypical or suspicious activities
 Suspend user accounts exhibiting suspicious activity
 Require users to log back in to Office 365 apps after an alert has been
triggered
 Lets you identify high-risk and abnormal usage
http://www.piasys.com/
Office 365 Unified Audit Logs
 Allows you to search logs for activities related to almost “everything”
 You can search by
 Target user(s)
 Date interval
 Files, Folders, Sites
 You can search online or you can export a CSV file for further analysis
 Provides information like
 Date, Client IP, User, Activity, Item, Details (JSON, depends on the service)
http://www.piasys.com/
Office 365 Unified Log Activities
• Files
• Folders
• Sharing and Access Requests
• Synchronizations
• Site Administration
• Exchange Mailboxes
• Sway
• User Administration
• Azure AD Group Administration
• Application Administration
• Role Administration
• Directory Administration
• eDiscovery
• Power BI
• Microsoft Teams
• Dynamic 365
• Microsoft Flow
http://www.piasys.com/
Demo
Office 365 Unified Logs
http://www.piasys.com/
Advanced Data Governance (ADG)
 Machine learning help customers find and retain important data
while eliminating trivial, redundant and obsolete data that could
cause risk if compromised
 Provides capabilities like:
 Proactive policy recommendations and automatic data classifications that
allow you take actions on data—such as retention and deletion—throughout
its lifecycle
 System default alerts to identify data governance risks, such as “Unusual
volume of file deletion,” as well as the ability to create custom alerts by
specifying alert matching conditions and threshold
 The ability to apply compliance controls to on-premises data by intelligently
filtering and migrating that data to Office 365
http://www.piasys.com/
SharePoint Online Site Classification
 Allows you to define site classification at Azure AD tenant level
 You need PowerShell to enable it
 While creating “modern” sites you can apply a classification
 Becomes a property (.Classification) of the Site Collection
 Can be used later on for governance purposes
 You can read it through CSOM, or REST
 You can use the Microsoft Graph for “modern” team sites, too
http://www.piasys.com/
Demo
SharePoint Online Site Classification
http://www.piasys.com/
GDPR Activity Hub
http://www.piasys.com/
What is the GDPR Activity Hub?
 Reference solution for Partners and Customers
 Ready to go portal
 Open source, related to the SharePoint PnP Project
 https://github.com/SharePoint/sp-dev-gdpr-activity-hub
 Based on tools, techniques, and patterns promoted by PnP
 Allows easy management of GDPR tasks and phases
 Based on Office 365 and SharePoint Online
 Showcase of Microsoft technologies’ capabilities
http://www.piasys.com/
Involved Technologies
 SharePoint Online modern sites
 SharePoint Framework client-side web parts
 Office 365 Groups/Microsoft Teams
 Remote provisioning
 Power BI
http://www.piasys.com/
Main Functionalities
 GDPR Dashboard
 Data repository based on SharePoint Online
 Custom pages for data management
 Insert Request client-side web part
 Insert Event/Incident client-side web part
 Basic sample flows for tasks management
 Tasks Management client-side web part
 GDPR Hierarchy client-side web part
 General capabilities
http://www.piasys.com/
General Capabilities
 Automated setup and provisioning
 General documentation
 Customizable model
 Open for community contribution
 It’s open source!
http://www.piasys.com/
Demo
Lap around GDPR Activity Hub
http://www.piasys.com/
Wrap up!
 Be prepared for GDPR
 Almost every business is impacted!
 Start the assessment of your IT infrastructure
 Think about moving to the cloud, if you are not there, yet …
 Give an eye to the GDPR Activity Hub
 Play with the FREE assessment tool:
 https://assets.microsoft.com/en-us/gdpr-detailed-assessment.zip
 Keep an eye on the GDPR section for Microsoft Partners
 http://aka.ms/gdprpartners
Governance and Risk Prevention for SharePoint
Customizing SharePoint lets you tailor the platform right to
your needs but it also opens up the potential for threats
What SharePoint customizations can technically do:
• Access your data
• Process your data
• Open the platform to external services
• Open the platform to external users
Rencore’s AnalysisCloud helps you to identify
data at risk.
rencore.com
Governance and Risk Prevention for SharePoint
AnalysisCloud brings governance and risk prevention to
SharePoint Online customizations.
AnalysisCloud:
• Discovers all customizations live in your SharePoint
• Analyzes customizations for potential and actual threats
• Continuously tracks and monitors existing and new
Learn more about AnalysisCloud:
https://try.rencore.cloud
rencore.com
rencore.com
Questions & Answers
Feel free to post your questions in the Q&A section
rencore.com
Thank you for attending!
The webinar recording will be sent to you later today.

More Related Content

What's hot

Universal Search for Legal Enterprises
Universal Search for Legal EnterprisesUniversal Search for Legal Enterprises
Universal Search for Legal EnterprisesAdhereSolutions
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365Joanne Klein
 
Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Craig Jahnke
 
Office 365 Security - MacGyver, Ninja or Swat team
Office 365 Security -  MacGyver, Ninja or Swat teamOffice 365 Security -  MacGyver, Ninja or Swat team
Office 365 Security - MacGyver, Ninja or Swat teamAntonioMaio2
 
Hybrid Identity Management with SharePoint and Office 365 - Antonio Maio
Hybrid Identity Management with SharePoint and Office 365 - Antonio MaioHybrid Identity Management with SharePoint and Office 365 - Antonio Maio
Hybrid Identity Management with SharePoint and Office 365 - Antonio MaioAntonioMaio2
 
Cryptzone SharePoint and Office 365 Security Solutions Guide
Cryptzone SharePoint and Office 365 Security Solutions GuideCryptzone SharePoint and Office 365 Security Solutions Guide
Cryptzone SharePoint and Office 365 Security Solutions GuideDavid J Rosenthal
 
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...NCCOMMS
 
M365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and HowM365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and HowJoanne Klein
 
What's new in Security and Compliance in SharePoint , OneDrive for Business &...
What's new in Security and Compliance in SharePoint , OneDrive for Business &...What's new in Security and Compliance in SharePoint , OneDrive for Business &...
What's new in Security and Compliance in SharePoint , OneDrive for Business &...Vignesh Ganesan I Microsoft MVP
 
SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365Joanne Klein
 
Office 365 security new innovations from microsoft ignite - antonio maio
Office 365 security   new innovations from microsoft ignite - antonio maioOffice 365 security   new innovations from microsoft ignite - antonio maio
Office 365 security new innovations from microsoft ignite - antonio maioAntonioMaio2
 
M365 Records Management Community Webinar
M365 Records Management Community WebinarM365 Records Management Community Webinar
M365 Records Management Community WebinarDrew Madelung
 
Office365 App Security
Office365 App SecurityOffice365 App Security
Office365 App SecurityOliver Wirkus
 
Microsoft Teams in the Modern Workplace
Microsoft Teams in the Modern WorkplaceMicrosoft Teams in the Modern Workplace
Microsoft Teams in the Modern WorkplaceJoanne Klein
 
Introduction to Records Management and Compliance in Office 365
Introduction to Records Management and Compliance in Office 365Introduction to Records Management and Compliance in Office 365
Introduction to Records Management and Compliance in Office 365Noorez Khamis
 
Security and Compliance in Office 365
Security and Compliance in Office 365Security and Compliance in Office 365
Security and Compliance in Office 365Joel Jeffery
 
Getting started with with SharePoint Syntex
Getting started with with SharePoint SyntexGetting started with with SharePoint Syntex
Getting started with with SharePoint SyntexDrew Madelung
 

What's hot (20)

Data governance in Office 365
Data governance in Office 365Data governance in Office 365
Data governance in Office 365
 
Universal Search for Legal Enterprises
Universal Search for Legal EnterprisesUniversal Search for Legal Enterprises
Universal Search for Legal Enterprises
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365
 
Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016
 
Security and compliance in Office 365 -Part 1
Security and compliance in Office 365 -Part 1Security and compliance in Office 365 -Part 1
Security and compliance in Office 365 -Part 1
 
Office 365 Security - MacGyver, Ninja or Swat team
Office 365 Security -  MacGyver, Ninja or Swat teamOffice 365 Security -  MacGyver, Ninja or Swat team
Office 365 Security - MacGyver, Ninja or Swat team
 
Hybrid Identity Management with SharePoint and Office 365 - Antonio Maio
Hybrid Identity Management with SharePoint and Office 365 - Antonio MaioHybrid Identity Management with SharePoint and Office 365 - Antonio Maio
Hybrid Identity Management with SharePoint and Office 365 - Antonio Maio
 
Information Governance in office 365 records management and retention
Information Governance in office 365 records management and retentionInformation Governance in office 365 records management and retention
Information Governance in office 365 records management and retention
 
Cryptzone SharePoint and Office 365 Security Solutions Guide
Cryptzone SharePoint and Office 365 Security Solutions GuideCryptzone SharePoint and Office 365 Security Solutions Guide
Cryptzone SharePoint and Office 365 Security Solutions Guide
 
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...
O365Con18 - Classify, Label and Protect your Data with Azure Information Prot...
 
M365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and HowM365 Virtual Marathon: Retention in Office 365 - the Where What and How
M365 Virtual Marathon: Retention in Office 365 - the Where What and How
 
What's new in Security and Compliance in SharePoint , OneDrive for Business &...
What's new in Security and Compliance in SharePoint , OneDrive for Business &...What's new in Security and Compliance in SharePoint , OneDrive for Business &...
What's new in Security and Compliance in SharePoint , OneDrive for Business &...
 
SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365SPFest Chicago - Information Management and Data Governance in Office 365
SPFest Chicago - Information Management and Data Governance in Office 365
 
Office 365 security new innovations from microsoft ignite - antonio maio
Office 365 security   new innovations from microsoft ignite - antonio maioOffice 365 security   new innovations from microsoft ignite - antonio maio
Office 365 security new innovations from microsoft ignite - antonio maio
 
M365 Records Management Community Webinar
M365 Records Management Community WebinarM365 Records Management Community Webinar
M365 Records Management Community Webinar
 
Office365 App Security
Office365 App SecurityOffice365 App Security
Office365 App Security
 
Microsoft Teams in the Modern Workplace
Microsoft Teams in the Modern WorkplaceMicrosoft Teams in the Modern Workplace
Microsoft Teams in the Modern Workplace
 
Introduction to Records Management and Compliance in Office 365
Introduction to Records Management and Compliance in Office 365Introduction to Records Management and Compliance in Office 365
Introduction to Records Management and Compliance in Office 365
 
Security and Compliance in Office 365
Security and Compliance in Office 365Security and Compliance in Office 365
Security and Compliance in Office 365
 
Getting started with with SharePoint Syntex
Getting started with with SharePoint SyntexGetting started with with SharePoint Syntex
Getting started with with SharePoint Syntex
 

Similar to Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Paolo Pialorsi

Microsoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance FrameworkMicrosoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance FrameworkAlistair Pugin
 
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...Sébastien Paulet
 
Proteccion de datos (DLP) usando MS 365-
Proteccion de datos (DLP) usando MS 365-Proteccion de datos (DLP) usando MS 365-
Proteccion de datos (DLP) usando MS 365-RalSejas
 
Office 365 Features for GDPR Compliance Webinar
Office 365 Features for GDPR Compliance WebinarOffice 365 Features for GDPR Compliance Webinar
Office 365 Features for GDPR Compliance WebinarNew Horizons Ireland
 
SharePoint Online vs. On-Premise
SharePoint Online vs. On-PremiseSharePoint Online vs. On-Premise
SharePoint Online vs. On-PremiseEvan Hodges
 
Microsoft 365 | Modern workplace
Microsoft 365 | Modern workplaceMicrosoft 365 | Modern workplace
Microsoft 365 | Modern workplaceSiddick Elaheebocus
 
B2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam LevithanB2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam LevithanSPS Paris
 
Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015Robert Crane
 
Office 365 for Business Demystified for the average Technology and Business P...
Office 365 for Business Demystified for the average Technology and Business P...Office 365 for Business Demystified for the average Technology and Business P...
Office 365 for Business Demystified for the average Technology and Business P...Noorez Khamis
 
Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDrew Madelung
 
June 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know WebinarJune 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know WebinarRobert Crane
 
SPUnite17 Information Management and Data Governance in Office365
SPUnite17 Information Management and Data Governance in Office365SPUnite17 Information Management and Data Governance in Office365
SPUnite17 Information Management and Data Governance in Office365NCCOMMS
 
Information management and data governance in Office 365
Information management and data governance in Office 365Information management and data governance in Office 365
Information management and data governance in Office 365Joanne Klein
 
SharePoint and GDPR Compliance
SharePoint and GDPR Compliance SharePoint and GDPR Compliance
SharePoint and GDPR Compliance SysKit Ltd
 
Security and Compliance with SharePoint and Office 365
Security and Compliance with SharePoint and Office 365Security and Compliance with SharePoint and Office 365
Security and Compliance with SharePoint and Office 365Richard Harbridge
 
Security, Administration & Governance for SharePoint On-Prem, Online, & Every...
Security, Administration & Governance for SharePoint On-Prem, Online, & Every...Security, Administration & Governance for SharePoint On-Prem, Online, & Every...
Security, Administration & Governance for SharePoint On-Prem, Online, & Every...Christian Buckley
 
Microsoft Azure Rights Management
Microsoft Azure Rights ManagementMicrosoft Azure Rights Management
Microsoft Azure Rights ManagementDavid J Rosenthal
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Andy Talbot
 
When Your CISO Says No - Security & Compliance in Office 365
When Your CISO Says No - Security & Compliance in Office 365When Your CISO Says No - Security & Compliance in Office 365
When Your CISO Says No - Security & Compliance in Office 365Ricardo Wilkins
 

Similar to Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Paolo Pialorsi (20)

Microsoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance FrameworkMicrosoft Information Protection: Your Security and Compliance Framework
Microsoft Information Protection: Your Security and Compliance Framework
 
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
 
Proteccion de datos (DLP) usando MS 365-
Proteccion de datos (DLP) usando MS 365-Proteccion de datos (DLP) usando MS 365-
Proteccion de datos (DLP) usando MS 365-
 
Office 365 Features for GDPR Compliance Webinar
Office 365 Features for GDPR Compliance WebinarOffice 365 Features for GDPR Compliance Webinar
Office 365 Features for GDPR Compliance Webinar
 
SharePoint Online vs. On-Premise
SharePoint Online vs. On-PremiseSharePoint Online vs. On-Premise
SharePoint Online vs. On-Premise
 
Microsoft 365 | Modern workplace
Microsoft 365 | Modern workplaceMicrosoft 365 | Modern workplace
Microsoft 365 | Modern workplace
 
B2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam LevithanB2 - The History of Content Security: Part 2 - Adam Levithan
B2 - The History of Content Security: Part 2 - Adam Levithan
 
Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015Office 365 Security, Privacy and Compliance - SMB Nation 2015
Office 365 Security, Privacy and Compliance - SMB Nation 2015
 
Office 365 for Business Demystified for the average Technology and Business P...
Office 365 for Business Demystified for the average Technology and Business P...Office 365 for Business Demystified for the average Technology and Business P...
Office 365 for Business Demystified for the average Technology and Business P...
 
Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss Prevention
 
June 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know WebinarJune 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know Webinar
 
SharePoint for Government
SharePoint for GovernmentSharePoint for Government
SharePoint for Government
 
SPUnite17 Information Management and Data Governance in Office365
SPUnite17 Information Management and Data Governance in Office365SPUnite17 Information Management and Data Governance in Office365
SPUnite17 Information Management and Data Governance in Office365
 
Information management and data governance in Office 365
Information management and data governance in Office 365Information management and data governance in Office 365
Information management and data governance in Office 365
 
SharePoint and GDPR Compliance
SharePoint and GDPR Compliance SharePoint and GDPR Compliance
SharePoint and GDPR Compliance
 
Security and Compliance with SharePoint and Office 365
Security and Compliance with SharePoint and Office 365Security and Compliance with SharePoint and Office 365
Security and Compliance with SharePoint and Office 365
 
Security, Administration & Governance for SharePoint On-Prem, Online, & Every...
Security, Administration & Governance for SharePoint On-Prem, Online, & Every...Security, Administration & Governance for SharePoint On-Prem, Online, & Every...
Security, Administration & Governance for SharePoint On-Prem, Online, & Every...
 
Microsoft Azure Rights Management
Microsoft Azure Rights ManagementMicrosoft Azure Rights Management
Microsoft Azure Rights Management
 
Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)Microsoft Cloud GDPR Compliance Options (SUGUK)
Microsoft Cloud GDPR Compliance Options (SUGUK)
 
When Your CISO Says No - Security & Compliance in Office 365
When Your CISO Says No - Security & Compliance in Office 365When Your CISO Says No - Security & Compliance in Office 365
When Your CISO Says No - Security & Compliance in Office 365
 

More from Rencore

Rencore Webinar: 10 things to keep an eye on to increase share point health
Rencore Webinar: 10 things to keep an eye on to increase share point healthRencore Webinar: 10 things to keep an eye on to increase share point health
Rencore Webinar: 10 things to keep an eye on to increase share point healthRencore
 
Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!
Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!
Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!Rencore
 
Rencore Webinar: Myth-busting GDPR in Office 365 & Azure
Rencore Webinar: Myth-busting GDPR in Office 365 & AzureRencore Webinar: Myth-busting GDPR in Office 365 & Azure
Rencore Webinar: Myth-busting GDPR in Office 365 & AzureRencore
 
Hugh Wood from Rencore: Development best practices for a new development worl...
Hugh Wood from Rencore: Development best practices for a new development worl...Hugh Wood from Rencore: Development best practices for a new development worl...
Hugh Wood from Rencore: Development best practices for a new development worl...Rencore
 
Matthias Einig from Rencore: Organizational considerations for customizing Sh...
Matthias Einig from Rencore: Organizational considerations for customizing Sh...Matthias Einig from Rencore: Organizational considerations for customizing Sh...
Matthias Einig from Rencore: Organizational considerations for customizing Sh...Rencore
 
Rencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
Rencore Webinar: Advanced Security Management within Office 365 with Liam ClearyRencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
Rencore Webinar: Advanced Security Management within Office 365 with Liam ClearyRencore
 
Rencore Webinar: Developing Secure and Performant JavaScript for SharePoint
Rencore Webinar: Developing Secure and Performant JavaScript for SharePointRencore Webinar: Developing Secure and Performant JavaScript for SharePoint
Rencore Webinar: Developing Secure and Performant JavaScript for SharePointRencore
 
Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...
Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...
Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...Rencore
 
Rencore Webinar: Securing Office 365 and Microsoft Azure like a Rockstar
Rencore Webinar: Securing Office 365 and Microsoft Azure like a RockstarRencore Webinar: Securing Office 365 and Microsoft Azure like a Rockstar
Rencore Webinar: Securing Office 365 and Microsoft Azure like a RockstarRencore
 
Rencore Webinar: SharePoint Customizations - the most overlooked road block t...
Rencore Webinar: SharePoint Customizations - the most overlooked road block t...Rencore Webinar: SharePoint Customizations - the most overlooked road block t...
Rencore Webinar: SharePoint Customizations - the most overlooked road block t...Rencore
 
You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...
You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...
You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...Rencore
 

More from Rencore (11)

Rencore Webinar: 10 things to keep an eye on to increase share point health
Rencore Webinar: 10 things to keep an eye on to increase share point healthRencore Webinar: 10 things to keep an eye on to increase share point health
Rencore Webinar: 10 things to keep an eye on to increase share point health
 
Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!
Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!
Provisioning SPFx Solutions to SharePoint Online using PnP, ALM APIs and more!
 
Rencore Webinar: Myth-busting GDPR in Office 365 & Azure
Rencore Webinar: Myth-busting GDPR in Office 365 & AzureRencore Webinar: Myth-busting GDPR in Office 365 & Azure
Rencore Webinar: Myth-busting GDPR in Office 365 & Azure
 
Hugh Wood from Rencore: Development best practices for a new development worl...
Hugh Wood from Rencore: Development best practices for a new development worl...Hugh Wood from Rencore: Development best practices for a new development worl...
Hugh Wood from Rencore: Development best practices for a new development worl...
 
Matthias Einig from Rencore: Organizational considerations for customizing Sh...
Matthias Einig from Rencore: Organizational considerations for customizing Sh...Matthias Einig from Rencore: Organizational considerations for customizing Sh...
Matthias Einig from Rencore: Organizational considerations for customizing Sh...
 
Rencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
Rencore Webinar: Advanced Security Management within Office 365 with Liam ClearyRencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
Rencore Webinar: Advanced Security Management within Office 365 with Liam Cleary
 
Rencore Webinar: Developing Secure and Performant JavaScript for SharePoint
Rencore Webinar: Developing Secure and Performant JavaScript for SharePointRencore Webinar: Developing Secure and Performant JavaScript for SharePoint
Rencore Webinar: Developing Secure and Performant JavaScript for SharePoint
 
Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...
Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...
Matthias Einig from Rencore - Transforming SharePoint farm solutions to the A...
 
Rencore Webinar: Securing Office 365 and Microsoft Azure like a Rockstar
Rencore Webinar: Securing Office 365 and Microsoft Azure like a RockstarRencore Webinar: Securing Office 365 and Microsoft Azure like a Rockstar
Rencore Webinar: Securing Office 365 and Microsoft Azure like a Rockstar
 
Rencore Webinar: SharePoint Customizations - the most overlooked road block t...
Rencore Webinar: SharePoint Customizations - the most overlooked road block t...Rencore Webinar: SharePoint Customizations - the most overlooked road block t...
Rencore Webinar: SharePoint Customizations - the most overlooked road block t...
 
You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...
You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...
You don’t know JS about SharePoint - Mastering javascript performance (Hugh W...
 

Recently uploaded

How to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationHow to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationBradBedford3
 
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmSujith Sukumaran
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanyChristoph Pohl
 
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...Cizo Technology Services
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio, Inc.
 
What is Advanced Excel and what are some best practices for designing and cre...
What is Advanced Excel and what are some best practices for designing and cre...What is Advanced Excel and what are some best practices for designing and cre...
What is Advanced Excel and what are some best practices for designing and cre...Technogeeks
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)jennyeacort
 
PREDICTING RIVER WATER QUALITY ppt presentation
PREDICTING  RIVER  WATER QUALITY  ppt presentationPREDICTING  RIVER  WATER QUALITY  ppt presentation
PREDICTING RIVER WATER QUALITY ppt presentationvaddepallysandeep122
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtimeandrehoraa
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...OnePlan Solutions
 
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Angel Borroy López
 
Best Web Development Agency- Idiosys USA.pdf
Best Web Development Agency- Idiosys USA.pdfBest Web Development Agency- Idiosys USA.pdf
Best Web Development Agency- Idiosys USA.pdfIdiosysTechnologies1
 
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesFolding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesPhilip Schwarz
 
React Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaReact Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaHanief Utama
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxTier1 app
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsAhmed Mohamed
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Andreas Granig
 
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWhat is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWave PLM
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based projectAnoyGreter
 
CRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceCRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceBrainSell Technologies
 

Recently uploaded (20)

How to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationHow to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion Application
 
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalm
 
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte GermanySuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
SuccessFactors 1H 2024 Release - Sneak-Peek by Deloitte Germany
 
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
Global Identity Enrolment and Verification Pro Solution - Cizo Technology Ser...
 
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed DataAlluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
Alluxio Monthly Webinar | Cloud-Native Model Training on Distributed Data
 
What is Advanced Excel and what are some best practices for designing and cre...
What is Advanced Excel and what are some best practices for designing and cre...What is Advanced Excel and what are some best practices for designing and cre...
What is Advanced Excel and what are some best practices for designing and cre...
 
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
Call Us🔝>༒+91-9711147426⇛Call In girls karol bagh (Delhi)
 
PREDICTING RIVER WATER QUALITY ppt presentation
PREDICTING  RIVER  WATER QUALITY  ppt presentationPREDICTING  RIVER  WATER QUALITY  ppt presentation
PREDICTING RIVER WATER QUALITY ppt presentation
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtime
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
 
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
Alfresco TTL#157 - Troubleshooting Made Easy: Deciphering Alfresco mTLS Confi...
 
Best Web Development Agency- Idiosys USA.pdf
Best Web Development Agency- Idiosys USA.pdfBest Web Development Agency- Idiosys USA.pdf
Best Web Development Agency- Idiosys USA.pdf
 
Folding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a seriesFolding Cheat Sheet #4 - fourth in a series
Folding Cheat Sheet #4 - fourth in a series
 
React Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaReact Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief Utama
 
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptxKnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
KnowAPIs-UnknownPerf-jaxMainz-2024 (1).pptx
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024
 
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWhat is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need It
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based project
 
CRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. SalesforceCRM Contender Series: HubSpot vs. Salesforce
CRM Contender Series: HubSpot vs. Salesforce
 

Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Paolo Pialorsi

  • 1. w: rencore.com | e: info@rencore.com | t: @rencoreab Manage Customization Risk and Save on Maintenance Costs! Customization governance, transformation and risk prevention for SharePoint & Office365 Understanding EU GDPR from an Office 365 perspective October 24th, 2017
  • 2. rencore.com Our Guest: Erwin van Hunen Microsoft MVP, MCM SharePoint PnP Core Team Product Owner - Transformation Your Host: Paolo Pialorsi Microsoft MVP, MCSM SharePoint PnP Core Team Founder & CEO of PiaSys
  • 3. rencore.com Q&A Please use the Q&A functionality in Zoom instead of chat. We will pick up some questions at the end and answer the others in the follow-up email. FAQ: Recording of this webinar? Yes, the session is recorded and you will get the recording later today.
  • 4. http://www.piasys.com/ Understanding EU GDPR from an Office 365 perspective Paolo Pialorsi - @PaoloPia Senior Consultant – PiaSys.com
  • 5. http://www.piasys.com/ Agenda  Why GDPR compliancy matters?  From an IT perspective  Office 365 and GDPR  GDPR Activity Hub
  • 7. http://www.piasys.com/ What is GDPR?  GDPR = General Data Protection Regulation  Regulation (EU) 2016/679  It will go LIVE on May 25, 2018  It’s a regulation not a directive  Regulation: Immediately applicable and enforceable by law in all Member States  Directive: needs to be transposed into national law by Member States  Scope: protection of data for all individuals in the EU
  • 8. http://www.piasys.com/ I’m outside EU, does it matter for me?  Yes it does!  If you process, hold, store, manage personal data of any EU resident …  … you need to be compliant with GDPR!  Regardless where you are and where your business is located!
  • 9. http://www.piasys.com/ Common definitions  Data Subject: an identified or identifiable natural person  Personal Data: any information relating to a Data Subject  Processing: any operation or set of operations which is performed on Personal Data or on sets of Personal Data
  • 10. http://www.piasys.com/ GDPR Roles  Data Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data  Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller  Data Protection Officer: provides guidance on the implementation of appropriate measures and on the demonstration of compliance
  • 11. http://www.piasys.com/ Key changes under GDPR Personal Privacy •Individuals have the right to: •Access their personal data •Correct errors in their personal data •Erase their personal data •Object to processing of their personal data •Export personal data Controls and notifications •Organizations will need to: • Protect personal data using appropriate security • Notify authorities of personal data breaches • Obtain appropriate consents for processing data • Keep records detailing data processing Transparent policies •Organizations are required to: • Provide clear notice of data collection • Outline processing purposes and use cases • Define data retention and deletion policies IT and training •Organizations will need to: • Train privacy personnel and employees • Audit and update data policies • Employ a Data Protection Officer (if required) • Create and manage compliant vendor contracts
  • 12. http://www.piasys.com/ Some IT requirements  You need to keep track of events like:  Data Breaches  Data Consent  Data Consent Withdrawal  Identity Risks/Theft  Data Processing  Data Archived  You need to collect requests for:  Data Access  Data Correction  Data Export  Data Processing Objection  Data Erase
  • 13. http://www.piasys.com/ Just to make an example …  As soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it  A supervisor authority can be a data protection authority (DPA)  Thus, you will need a workflow process for Data Breaches!
  • 15. http://www.piasys.com/ In February 2017, Microsoft announced that its cloud services will comply with GDPR by May 25, 2018
  • 16. http://www.piasys.com/ Main capabilities of Office 365 for GDPR compliancy • Tooling • Office 365 Secure Score • Data Loss Prevention (DLP) • Office 365 eDiscovery • Customer Lockbox • Monitoring & Logging • Advanced Threat Protection • Threat Intelligence • Cloud App Security • Office 365 Unified Audit Logs • Governance • Advanced Data Governance (ADG) • SharePoint Online Site Classification • Reporting • Security & Compliance Reports • Risk & Compliance Dashboard
  • 17. http://www.piasys.com/ Office 365 Secure Score  Accessible to all admins  Based on the services you are using  Compares your services settings with a baseline provided by Microsoft  Gives you an “actions” queue to accomplish to improve your score  Provides detailed instructions about what to do  Whatever will be your score …  … there is no guarantee that you will not be breached …
  • 19. http://www.piasys.com/ Data Loss Prevention  Enable you to identify sensitive/personal data as it travels through Exchange Online, SharePoint Online, and OneDrive for Business  You can use it to  Identify sensitive information across many locations (SharePoint Online, Exchange Online, OneDrive for Business)  Prevent accidental sharing of such sensitive information  Monitor and protect from sharing sensitive data inside client applications  Excel 2016, Word 2016, PowerPoint 2016  Help user stay compliant  Collect data and view DLP reports about content matching policies
  • 20. http://www.piasys.com/ Anatomy of DLP Policies  Locations: SPO, EXO,OD4B  Rules  One or more for each policy  Conditions and Actions  Conditions  Content: Classification  Labels / Sensitive Information Types  Context: inside/outside tenant  Actions  Restrict access to content
  • 22. http://www.piasys.com/ DLP Reporting  Various reports available out of the box  Top DLP policy matches for mail  Top DLP rule matches for mail  DLP policy matches by severity for mail  DLP policy matches, overrides, and false positives for mail
  • 24. http://www.piasys.com/ Office 365 eDiscovery  In-place eDiscovery for investigating cases and search for related content  Provides hold, analyze, and export capabilities  Targets almost every content in your organization  Email  Documents  Skype for Business conversations  Teams data  Etc.  Advanced eDiscovery leverages  Machine learning  Predictive coding  Text analytics
  • 25. http://www.piasys.com/ Customer Lockbox  Ensures that Microsoft engineer does not get access to the customer’s content without customer’s explicit approval  All access is obtained through a rigorous access control technology  Administrators can approve or reject the request  Customer Lockbox requests have a default lifetime of 12 hours  You need Office 365 E5 or you have to buy the functionality separately
  • 27. http://www.piasys.com/ Advanced Threat Protection  Cloud-based email filtering service  Helps protect email against unknown, sophisticated malware attacks  Main functionalities  Anti-malware  Safe links  Safe attachments  Spoof intelligence  Quarantine  Advanced anti-phishing capabilities  DKIM (DomainKeys Identified Mail)  Provides reach reporting and tracking
  • 28. http://www.piasys.com/ Threat Intelligence  Helps you proactively uncover and protect against advanced threats in Office 365  Office 365 Threat Intelligence monitors signals from sources  User activity  Authentication  Email  Compromised PCs  Security incidents  Provides tools like  Threat dashboard  Threat explorer  Incidents  Threat Intelligence Feeds  Integration with Windows Defender
  • 29. http://www.piasys.com/ Cloud App Security  AKA “Advanced Security Management”  Gives you insights into suspicious activity in Office 365  See how your organization's data in Office 365 is accessed and used  Define policies that trigger alerts for atypical or suspicious activities  Suspend user accounts exhibiting suspicious activity  Require users to log back in to Office 365 apps after an alert has been triggered  Lets you identify high-risk and abnormal usage
  • 30. http://www.piasys.com/ Office 365 Unified Audit Logs  Allows you to search logs for activities related to almost “everything”  You can search by  Target user(s)  Date interval  Files, Folders, Sites  You can search online or you can export a CSV file for further analysis  Provides information like  Date, Client IP, User, Activity, Item, Details (JSON, depends on the service)
  • 31. http://www.piasys.com/ Office 365 Unified Log Activities • Files • Folders • Sharing and Access Requests • Synchronizations • Site Administration • Exchange Mailboxes • Sway • User Administration • Azure AD Group Administration • Application Administration • Role Administration • Directory Administration • eDiscovery • Power BI • Microsoft Teams • Dynamic 365 • Microsoft Flow
  • 33. http://www.piasys.com/ Advanced Data Governance (ADG)  Machine learning help customers find and retain important data while eliminating trivial, redundant and obsolete data that could cause risk if compromised  Provides capabilities like:  Proactive policy recommendations and automatic data classifications that allow you take actions on data—such as retention and deletion—throughout its lifecycle  System default alerts to identify data governance risks, such as “Unusual volume of file deletion,” as well as the ability to create custom alerts by specifying alert matching conditions and threshold  The ability to apply compliance controls to on-premises data by intelligently filtering and migrating that data to Office 365
  • 34. http://www.piasys.com/ SharePoint Online Site Classification  Allows you to define site classification at Azure AD tenant level  You need PowerShell to enable it  While creating “modern” sites you can apply a classification  Becomes a property (.Classification) of the Site Collection  Can be used later on for governance purposes  You can read it through CSOM, or REST  You can use the Microsoft Graph for “modern” team sites, too
  • 37. http://www.piasys.com/ What is the GDPR Activity Hub?  Reference solution for Partners and Customers  Ready to go portal  Open source, related to the SharePoint PnP Project  https://github.com/SharePoint/sp-dev-gdpr-activity-hub  Based on tools, techniques, and patterns promoted by PnP  Allows easy management of GDPR tasks and phases  Based on Office 365 and SharePoint Online  Showcase of Microsoft technologies’ capabilities
  • 38. http://www.piasys.com/ Involved Technologies  SharePoint Online modern sites  SharePoint Framework client-side web parts  Office 365 Groups/Microsoft Teams  Remote provisioning  Power BI
  • 39. http://www.piasys.com/ Main Functionalities  GDPR Dashboard  Data repository based on SharePoint Online  Custom pages for data management  Insert Request client-side web part  Insert Event/Incident client-side web part  Basic sample flows for tasks management  Tasks Management client-side web part  GDPR Hierarchy client-side web part  General capabilities
  • 40. http://www.piasys.com/ General Capabilities  Automated setup and provisioning  General documentation  Customizable model  Open for community contribution  It’s open source!
  • 42. http://www.piasys.com/ Wrap up!  Be prepared for GDPR  Almost every business is impacted!  Start the assessment of your IT infrastructure  Think about moving to the cloud, if you are not there, yet …  Give an eye to the GDPR Activity Hub  Play with the FREE assessment tool:  https://assets.microsoft.com/en-us/gdpr-detailed-assessment.zip  Keep an eye on the GDPR section for Microsoft Partners  http://aka.ms/gdprpartners
  • 43. Governance and Risk Prevention for SharePoint Customizing SharePoint lets you tailor the platform right to your needs but it also opens up the potential for threats What SharePoint customizations can technically do: • Access your data • Process your data • Open the platform to external services • Open the platform to external users Rencore’s AnalysisCloud helps you to identify data at risk. rencore.com
  • 44. Governance and Risk Prevention for SharePoint AnalysisCloud brings governance and risk prevention to SharePoint Online customizations. AnalysisCloud: • Discovers all customizations live in your SharePoint • Analyzes customizations for potential and actual threats • Continuously tracks and monitors existing and new Learn more about AnalysisCloud: https://try.rencore.cloud rencore.com
  • 45. rencore.com Questions & Answers Feel free to post your questions in the Q&A section
  • 46. rencore.com Thank you for attending! The webinar recording will be sent to you later today.