SlideShare una empresa de Scribd logo
1 de 41
- Internal -
IS/DPP Baseline Training
E-learning – Part 3 – Data & Classification
Data in the Center
Environment
Physical
Human
Device
Application
Repository
Carrier
Network
Data
3rd Parties
3
- Internal - Page
No Data, No Worries: Data Minimization
4
- Internal - Page
Don’t Spread the Word
Information Classification
6
- Internal - Page
Why?
7
- Internal - Page
Data is everywhere, we organise it, to be able to manage it
8
- Internal - Page
Levels of Organising data
1,267.04 EURCardholder C
Shop N249.99 EUR
319.00 EUR
1,415.00 EUR
14/8
20/8
26/8
2/8
x 0.5 loyalty points
3,251.03 EUR
1,625
Shop M
Shop O
Shop P
Total for August
Loyalty points
9
- Internal - Page
Data / Information
10
- Internal - Page
Data that gives ABC a Competitive Advantage
 Indicator: “confidential” nature
11
- Internal - Page
Data that gives ABC a Competitive Advantage
 Examples “in scope”:
– Creative Ideas
– Strategy
 Indicator: “confidential” nature
12
- Internal - Page
Data that gives ABC a Competitive Advantage
 Examples “in scope”:
– Creative Ideas
– Strategy
– Contracts with customers
– Policies on rebates, complaint
compensation,…
 Indicator: “confidential” nature
13
- Internal - Page
Data that gives ABC a Competitive Advantage
 Examples “in scope”:
– Creative Ideas
– Strategy
– Contracts with customers
– Policies on rebates, complaint
compensation,…
– Personal Data (PDP Act / GDPR)
 Information related to identified or
identifiable natural person
– Cardholder data (PCI-DSS)
 Transaction data
 Indicator: “confidential” nature
14
- Internal - Page
Data that gives ABC a Competitive Advantage
 Examples “in scope”:
– Creative Ideas
– Strategy
– Contracts with customers
– Policies on rebates, complaint
compensation,…
– Personal Data (PDP Act)
 Information related to identified or
identifiable natural person
– Cardholder data (PCI-DSS)
 Transaction data
 Indicator: “confidential” nature
15
- Internal - Page
Processing personal data
HAVE TO: Data Protection Act / GDPR
16
- Internal - Page
Data Protection Act - Personal data
Any information
relating to
an identified or identifiable
natural person.
17
- Internal - Page
Data Protection Act - Personal data
In general not legal persons (e.g. limited companies)
BUT
- In some countries similar regime for legal persons
- Next to personal data protection there may be a
(professional) duty of confidentiality.
e.g. consumer customers, staff
members, individuals related to
corporations (legal
representatives, UBOs, …),
Any information
relating to
an identified or identifiable
natural person
18
- Internal - Page
Data Protection Act - Personal data
An identifiable person is one who can be
identified, directly or indirectly, in particular by
reference to
• An identification number or
•To one or more factors specific to his physical,
physiological, mental, economic, cultural or
social identity.
Any information
relating to
an identified or identifiable
natural person
19
- Internal - Page
Data Protection Act - Personal data
Any information
relating to
an identified or identifiable
natural person
20
- Internal - Page
Data Protection Act - Personal data
Any information
relating to
an identified or identifiable
natural person
21
- Internal - Page
Data Protection Act - Personal data
Any information
relating to
an identified or identifiable
natural person
22
- Internal - Page
Data
Subject
Processing personal data
Data Protection Act – Data Subject
23
- Internal - Page
Data Protection Act - Personal data
(perception of) “sensitivity”/”intimacy” is irrelevant
Any information
relating to
an identified or identifiable
natural person
24
- Internal - Page
Your CardYour Card and how you use it
25
- Internal - Page
Your CardYour Card and how you use it
26
- Internal - Page
Your CardYour Card and how you use it
27
- Internal - Page
Your Search Results
28
- Internal - Page
Your Phone Number
29
- Internal - Page
Your Location
30
- Internal - Page
Your Heartbeat
31
- Internal - Page
Your Keystroke Speed
32
- Internal - Page
Your Shoe Size
33
- Internal - Page
Data Protection Act / GDPR - Personal data
Any information
relating to
an identified or identifiable
natural person.
34
- Internal - Page
Data Protection - Processing
digital AND paper
35
- Internal - Page
Data Protection - Processing
Collection, recording, organization,
Storage,
Adaptation or alteration, rectification,
retrieval, consultation, use,
Disclosure by
transmission,
dissemination or otherwise
making available,
alignment or combination,
Blocking, erasure or
destruction
36
- Internal - Page
Data
Subject
Processing personal data
Data
Controller
Data Protection Act / GDPR – Data Controller
37
- Internal - Page
Processing personal data
Data Protection Act / GDPR – Data Controller
Data
Subject
Data
Controller
Bank ABC
Application form
38
- Internal - Page
Control
Processing personal data
Data Protection Act / GDPR – Control in 4 Pillars
Data
Subject
Data
Controller
39
- Internal - Page
Control
Processing personal data
Finality
Data Protection Act / GDPR – Control in 4 Pillars
Respect the
(original) purpose
Data
Subject
Data
Controller
Legitimacy
Have one of the
legal bases
40
- Internal - Page
Control
Processing personal data
Finality Legitimacy
Transparency
Data Protection Act / GDPR – Control in 4 Pillars
Respect the
(original) purpose
Have one of the
legal bases
Inform data subject
and sometimes
authorities
Data
Subject
Data
Controller
41
- Internal - Page
Control
Processing personal data
Finality Legitimacy
Transparency Organisation
Data Protection Act / GDPR – Control in 4 Pillars
Respect the
(original) purpose
Have one of the
legal bases
Inform data subject
and sometimes
authorities
Accountability and
technical and
organisational measures
Data
Subject
Data
Controller

Más contenido relacionado

La actualidad más candente

GDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality OwnersGDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality OwnersBoostly
 
The GDPR for B2B Marketers
The GDPR for B2B MarketersThe GDPR for B2B Marketers
The GDPR for B2B MarketersDemandbase
 
Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...
Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...
Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...Smart E-Commerce Network
 
Chp12 economics, global and other issues in ec
Chp12 economics, global and other  issues in ecChp12 economics, global and other  issues in ec
Chp12 economics, global and other issues in ecEngr Razaque
 
GDPR: Impact on DB design
GDPR: Impact on DB designGDPR: Impact on DB design
GDPR: Impact on DB designTrivadis
 
GDPR and Whois at ICANN
GDPR and Whois at ICANNGDPR and Whois at ICANN
GDPR and Whois at ICANNAPNIC
 
KK Legal Law Firm - Who we are & What we do
KK Legal Law Firm - Who we are & What we doKK Legal Law Firm - Who we are & What we do
KK Legal Law Firm - Who we are & What we dokklegal99
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in BerlinMailjet
 
When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
When Big Data is Personal Data - Data Analytics in The Age of Privacy LawsWhen Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
When Big Data is Personal Data - Data Analytics in The Age of Privacy LawsTara Aaron
 
New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18
New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18
New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18Inga Romanoff
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...CILIPScotland
 
New developments in corporate registration Carsten Schmidt & Dirk Krusche
New developments in corporate registration   Carsten Schmidt & Dirk KruscheNew developments in corporate registration   Carsten Schmidt & Dirk Krusche
New developments in corporate registration Carsten Schmidt & Dirk KruscheCorporate Registers Forum
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinWhitmeyerTuffin
 

La actualidad más candente (16)

GDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality OwnersGDPR Explained in Simple Terms for Hospitality Owners
GDPR Explained in Simple Terms for Hospitality Owners
 
The GDPR for B2B Marketers
The GDPR for B2B MarketersThe GDPR for B2B Marketers
The GDPR for B2B Marketers
 
Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...
Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...
Legally Sound in 2019 - Update on Legal Changes in E-Commerce: Martin Hahn (H...
 
Chp12 economics, global and other issues in ec
Chp12 economics, global and other  issues in ecChp12 economics, global and other  issues in ec
Chp12 economics, global and other issues in ec
 
GDPR: Impact on DB design
GDPR: Impact on DB designGDPR: Impact on DB design
GDPR: Impact on DB design
 
GDPR and Whois at ICANN
GDPR and Whois at ICANNGDPR and Whois at ICANN
GDPR and Whois at ICANN
 
ENTITY EXCHANGE FOR BUY-SIDE FIRMS
ENTITY EXCHANGE FOR BUY-SIDE FIRMSENTITY EXCHANGE FOR BUY-SIDE FIRMS
ENTITY EXCHANGE FOR BUY-SIDE FIRMS
 
KK Legal Law Firm - Who we are & What we do
KK Legal Law Firm - Who we are & What we doKK Legal Law Firm - Who we are & What we do
KK Legal Law Firm - Who we are & What we do
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
L3 presentation14
L3 presentation14L3 presentation14
L3 presentation14
 
When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
When Big Data is Personal Data - Data Analytics in The Age of Privacy LawsWhen Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
When Big Data is Personal Data - Data Analytics in The Age of Privacy Laws
 
New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18
New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18
New York Marketo User Group Meetup: GDPR for Marketers - DECODED 6.15.18
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
 
E Marketing
E MarketingE Marketing
E Marketing
 
New developments in corporate registration Carsten Schmidt & Dirk Krusche
New developments in corporate registration   Carsten Schmidt & Dirk KruscheNew developments in corporate registration   Carsten Schmidt & Dirk Krusche
New developments in corporate registration Carsten Schmidt & Dirk Krusche
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 

Similar a IS/DPP for staff #3a - Data

GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?MediaPost
 
GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?MediaPost
 
O365Con18 - Big Data - Sasha Fredrich
O365Con18 - Big Data - Sasha FredrichO365Con18 - Big Data - Sasha Fredrich
O365Con18 - Big Data - Sasha FredrichNCCOMMS
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-finalDr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalDr. Donald Macfarlane
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)Bright
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)Napier University
 
Infants and guns - data, digital analytics strategy and ethics - superweek 20...
Infants and guns - data, digital analytics strategy and ethics - superweek 20...Infants and guns - data, digital analytics strategy and ethics - superweek 20...
Infants and guns - data, digital analytics strategy and ethics - superweek 20...Steen Rasmussen
 
Maximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....LegallyMaximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....LegallyMediaPost
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-LatemAnn Van den Bunder
 
How GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect EveryoneHow GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect EveryoneThomas Goubau
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationcaniceconsulting
 
Who needs a EU representative according to GDPR article 27?
Who needs a EU representative according to GDPR article 27?Who needs a EU representative according to GDPR article 27?
Who needs a EU representative according to GDPR article 27?idc-representative
 
IS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data ClassificationIS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data ClassificationTommy Vandepitte
 
Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...
Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...
Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...Vivastream
 
GDPR & SAP: practical data governance & management activities
GDPR & SAP: practical data governance & management activitiesGDPR & SAP: practical data governance & management activities
GDPR & SAP: practical data governance & management activitiesNico J.W. Kuijper ECMm BPMs ERMp
 

Similar a IS/DPP for staff #3a - Data (20)

GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?GDPR Is Coming – Are Search Marketers Ready?
GDPR Is Coming – Are Search Marketers Ready?
 
GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?GDPR Is Coming – Are Emailers Ready?
GDPR Is Coming – Are Emailers Ready?
 
O365Con18 - Big Data - Sasha Fredrich
O365Con18 - Big Data - Sasha FredrichO365Con18 - Big Data - Sasha Fredrich
O365Con18 - Big Data - Sasha Fredrich
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)An Introduction to the General Data Protection Regulation (GDPR)
An Introduction to the General Data Protection Regulation (GDPR)
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 
Infants and guns - data, digital analytics strategy and ethics - superweek 20...
Infants and guns - data, digital analytics strategy and ethics - superweek 20...Infants and guns - data, digital analytics strategy and ethics - superweek 20...
Infants and guns - data, digital analytics strategy and ethics - superweek 20...
 
Maximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....LegallyMaximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....Legally
 
Gdpr and smart cities
Gdpr and smart citiesGdpr and smart cities
Gdpr and smart cities
 
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
2018 02 20 GDPR SEMINAR - Gemeente Sint-Martens-Latem
 
How GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect EveryoneHow GDPR will change Personal Data Control and Affect Everyone
How GDPR will change Personal Data Control and Affect Everyone
 
Materializing dataprivacy in SAP - How?
Materializing dataprivacy in SAP - How?Materializing dataprivacy in SAP - How?
Materializing dataprivacy in SAP - How?
 
Materializing dataprivacy in sap .. how?
Materializing dataprivacy in sap .. how?Materializing dataprivacy in sap .. how?
Materializing dataprivacy in sap .. how?
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
 
Who needs a EU representative according to GDPR article 27?
Who needs a EU representative according to GDPR article 27?Who needs a EU representative according to GDPR article 27?
Who needs a EU representative according to GDPR article 27?
 
IS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data ClassificationIS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data Classification
 
Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...
Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...
Is More Data Always Better? The Legal Risks of Data Collection, Storage and U...
 
GDPR & SAP: practical data governance & management activities
GDPR & SAP: practical data governance & management activitiesGDPR & SAP: practical data governance & management activities
GDPR & SAP: practical data governance & management activities
 
Gdpr and smart cities
Gdpr and smart citiesGdpr and smart cities
Gdpr and smart cities
 

Más de Tommy Vandepitte

Gegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdrachtGegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdrachtTommy Vandepitte
 
20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)Tommy Vandepitte
 
GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)Tommy Vandepitte
 
Controller-to-processor agreements
Controller-to-processor agreementsController-to-processor agreements
Controller-to-processor agreementsTommy Vandepitte
 
Gegevensbescherming makelaars
Gegevensbescherming makelaarsGegevensbescherming makelaars
Gegevensbescherming makelaarsTommy Vandepitte
 
EEAS - Cultivate your data protection
EEAS - Cultivate your data protectionEEAS - Cultivate your data protection
EEAS - Cultivate your data protectionTommy Vandepitte
 
Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130Tommy Vandepitte
 
Training privacy by design
Training privacy by designTraining privacy by design
Training privacy by designTommy Vandepitte
 
GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)Tommy Vandepitte
 
GDPR project board deck (example)
GDPR project board deck (example)GDPR project board deck (example)
GDPR project board deck (example)Tommy Vandepitte
 
IS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - MonitoringIS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - MonitoringTommy Vandepitte
 
IS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - IncidentsIS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - IncidentsTommy Vandepitte
 
IS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable useIS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable useTommy Vandepitte
 
IS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - PasswordsIS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - PasswordsTommy Vandepitte
 
IS/DPP for staff #5a - Access
IS/DPP for staff #5a - AccessIS/DPP for staff #5a - Access
IS/DPP for staff #5a - AccessTommy Vandepitte
 
IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?Tommy Vandepitte
 
IS/DPP for staff #1 - intro
IS/DPP for staff #1 - introIS/DPP for staff #1 - intro
IS/DPP for staff #1 - introTommy Vandepitte
 
Training Information Asset Owners
Training Information Asset OwnersTraining Information Asset Owners
Training Information Asset OwnersTommy Vandepitte
 

Más de Tommy Vandepitte (20)

DPIA template
DPIA templateDPIA template
DPIA template
 
Gegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdrachtGegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdracht
 
20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)
 
GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)
 
Controller-to-processor agreements
Controller-to-processor agreementsController-to-processor agreements
Controller-to-processor agreements
 
Gegevensbescherming makelaars
Gegevensbescherming makelaarsGegevensbescherming makelaars
Gegevensbescherming makelaars
 
EEAS - Cultivate your data protection
EEAS - Cultivate your data protectionEEAS - Cultivate your data protection
EEAS - Cultivate your data protection
 
Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130
 
Training privacy by design
Training privacy by designTraining privacy by design
Training privacy by design
 
GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)
 
GDPR project board deck (example)
GDPR project board deck (example)GDPR project board deck (example)
GDPR project board deck (example)
 
IS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - MonitoringIS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - Monitoring
 
IS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - IncidentsIS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - Incidents
 
IS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable useIS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable use
 
IS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - PasswordsIS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - Passwords
 
IS/DPP for staff #5a - Access
IS/DPP for staff #5a - AccessIS/DPP for staff #5a - Access
IS/DPP for staff #5a - Access
 
IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?
 
IS/DPP for staff #1 - intro
IS/DPP for staff #1 - introIS/DPP for staff #1 - intro
IS/DPP for staff #1 - intro
 
Training Procurement
Training ProcurementTraining Procurement
Training Procurement
 
Training Information Asset Owners
Training Information Asset OwnersTraining Information Asset Owners
Training Information Asset Owners
 

Último

Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Mark Reed
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfJemuel Francisco
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designMIPLM
 
Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Celine George
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parentsnavabharathschool99
 
ENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choomENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choomnelietumpap1
 
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfErwinPantujan2
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxiammrhaywood
 
Culture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptxCulture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptxPoojaSen20
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptxmary850239
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONHumphrey A Beña
 
Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17Celine George
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Jisc
 
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfAMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfphamnguyenenglishnb
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...Nguyen Thanh Tu Collection
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...JhezDiaz1
 
Judging the Relevance and worth of ideas part 2.pptx
Judging the Relevance  and worth of ideas part 2.pptxJudging the Relevance  and worth of ideas part 2.pptx
Judging the Relevance and worth of ideas part 2.pptxSherlyMaeNeri
 
FILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipinoFILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipinojohnmickonozaleda
 

Último (20)

Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-design
 
Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17
 
Choosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for ParentsChoosing the Right CBSE School A Comprehensive Guide for Parents
Choosing the Right CBSE School A Comprehensive Guide for Parents
 
ENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choomENGLISH6-Q4-W3.pptxqurter our high choom
ENGLISH6-Q4-W3.pptxqurter our high choom
 
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
 
Culture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptxCulture Uniformity or Diversity IN SOCIOLOGY.pptx
Culture Uniformity or Diversity IN SOCIOLOGY.pptx
 
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptxFINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
 
Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17Field Attribute Index Feature in Odoo 17
Field Attribute Index Feature in Odoo 17
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
 
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfAMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
 
Judging the Relevance and worth of ideas part 2.pptx
Judging the Relevance  and worth of ideas part 2.pptxJudging the Relevance  and worth of ideas part 2.pptx
Judging the Relevance and worth of ideas part 2.pptx
 
FILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipinoFILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipino
 

IS/DPP for staff #3a - Data

  • 1. - Internal - IS/DPP Baseline Training E-learning – Part 3 – Data & Classification
  • 2. Data in the Center Environment Physical Human Device Application Repository Carrier Network Data 3rd Parties
  • 3. 3 - Internal - Page No Data, No Worries: Data Minimization
  • 4. 4 - Internal - Page Don’t Spread the Word
  • 6. 6 - Internal - Page Why?
  • 7. 7 - Internal - Page Data is everywhere, we organise it, to be able to manage it
  • 8. 8 - Internal - Page Levels of Organising data 1,267.04 EURCardholder C Shop N249.99 EUR 319.00 EUR 1,415.00 EUR 14/8 20/8 26/8 2/8 x 0.5 loyalty points 3,251.03 EUR 1,625 Shop M Shop O Shop P Total for August Loyalty points
  • 9. 9 - Internal - Page Data / Information
  • 10. 10 - Internal - Page Data that gives ABC a Competitive Advantage  Indicator: “confidential” nature
  • 11. 11 - Internal - Page Data that gives ABC a Competitive Advantage  Examples “in scope”: – Creative Ideas – Strategy  Indicator: “confidential” nature
  • 12. 12 - Internal - Page Data that gives ABC a Competitive Advantage  Examples “in scope”: – Creative Ideas – Strategy – Contracts with customers – Policies on rebates, complaint compensation,…  Indicator: “confidential” nature
  • 13. 13 - Internal - Page Data that gives ABC a Competitive Advantage  Examples “in scope”: – Creative Ideas – Strategy – Contracts with customers – Policies on rebates, complaint compensation,… – Personal Data (PDP Act / GDPR)  Information related to identified or identifiable natural person – Cardholder data (PCI-DSS)  Transaction data  Indicator: “confidential” nature
  • 14. 14 - Internal - Page Data that gives ABC a Competitive Advantage  Examples “in scope”: – Creative Ideas – Strategy – Contracts with customers – Policies on rebates, complaint compensation,… – Personal Data (PDP Act)  Information related to identified or identifiable natural person – Cardholder data (PCI-DSS)  Transaction data  Indicator: “confidential” nature
  • 15. 15 - Internal - Page Processing personal data HAVE TO: Data Protection Act / GDPR
  • 16. 16 - Internal - Page Data Protection Act - Personal data Any information relating to an identified or identifiable natural person.
  • 17. 17 - Internal - Page Data Protection Act - Personal data In general not legal persons (e.g. limited companies) BUT - In some countries similar regime for legal persons - Next to personal data protection there may be a (professional) duty of confidentiality. e.g. consumer customers, staff members, individuals related to corporations (legal representatives, UBOs, …), Any information relating to an identified or identifiable natural person
  • 18. 18 - Internal - Page Data Protection Act - Personal data An identifiable person is one who can be identified, directly or indirectly, in particular by reference to • An identification number or •To one or more factors specific to his physical, physiological, mental, economic, cultural or social identity. Any information relating to an identified or identifiable natural person
  • 19. 19 - Internal - Page Data Protection Act - Personal data Any information relating to an identified or identifiable natural person
  • 20. 20 - Internal - Page Data Protection Act - Personal data Any information relating to an identified or identifiable natural person
  • 21. 21 - Internal - Page Data Protection Act - Personal data Any information relating to an identified or identifiable natural person
  • 22. 22 - Internal - Page Data Subject Processing personal data Data Protection Act – Data Subject
  • 23. 23 - Internal - Page Data Protection Act - Personal data (perception of) “sensitivity”/”intimacy” is irrelevant Any information relating to an identified or identifiable natural person
  • 24. 24 - Internal - Page Your CardYour Card and how you use it
  • 25. 25 - Internal - Page Your CardYour Card and how you use it
  • 26. 26 - Internal - Page Your CardYour Card and how you use it
  • 27. 27 - Internal - Page Your Search Results
  • 28. 28 - Internal - Page Your Phone Number
  • 29. 29 - Internal - Page Your Location
  • 30. 30 - Internal - Page Your Heartbeat
  • 31. 31 - Internal - Page Your Keystroke Speed
  • 32. 32 - Internal - Page Your Shoe Size
  • 33. 33 - Internal - Page Data Protection Act / GDPR - Personal data Any information relating to an identified or identifiable natural person.
  • 34. 34 - Internal - Page Data Protection - Processing digital AND paper
  • 35. 35 - Internal - Page Data Protection - Processing Collection, recording, organization, Storage, Adaptation or alteration, rectification, retrieval, consultation, use, Disclosure by transmission, dissemination or otherwise making available, alignment or combination, Blocking, erasure or destruction
  • 36. 36 - Internal - Page Data Subject Processing personal data Data Controller Data Protection Act / GDPR – Data Controller
  • 37. 37 - Internal - Page Processing personal data Data Protection Act / GDPR – Data Controller Data Subject Data Controller Bank ABC Application form
  • 38. 38 - Internal - Page Control Processing personal data Data Protection Act / GDPR – Control in 4 Pillars Data Subject Data Controller
  • 39. 39 - Internal - Page Control Processing personal data Finality Data Protection Act / GDPR – Control in 4 Pillars Respect the (original) purpose Data Subject Data Controller Legitimacy Have one of the legal bases
  • 40. 40 - Internal - Page Control Processing personal data Finality Legitimacy Transparency Data Protection Act / GDPR – Control in 4 Pillars Respect the (original) purpose Have one of the legal bases Inform data subject and sometimes authorities Data Subject Data Controller
  • 41. 41 - Internal - Page Control Processing personal data Finality Legitimacy Transparency Organisation Data Protection Act / GDPR – Control in 4 Pillars Respect the (original) purpose Have one of the legal bases Inform data subject and sometimes authorities Accountability and technical and organisational measures Data Subject Data Controller

Notas del editor

  1. Welcome to the third part of the baseline training IS/DPP. Herein we look at data and the different classifications we give it in order to be able to better handle it.
  2. In IS/DPP we basically set up a number of measures to protect our data, or as we call it in the jargon “information assets”. Around those we build a number of layers of security. And those layers interconnect and overlap. But data is always in the center. So that is where we start.
  3. Not having data is the easiest way to protect it. Obviously as a company and especially one where data is at the core of our activity, not having data is not an option. But… it is always good to keep in mind that when we don’t need the data, it is best not to collect it. when we no longer need the data, to delete it. as much as possible, avoid duplication.
  4. An example is a journalist protecting his source by not revealing its identity to anybody.
  5. Of course even respecting data minimization, we are still left with quite a large collection of all different types of data. And when we have data, we need the classify it.
  6. Why? Because data is such a broad concept, that in our digital world can boil down to zeros and ones, looking at it at that level would make no sense.
  7. That is why we create order out of the chaos data is, by putting it together in data sets that make sense. In theory we call that “information”.
  8. So a number would be data. A number and the currency “euro” would already make some sense. That amount of money connected to a sender (the cardholder) and a receiver (the shap) makes a fine transaction. All transactions in a month for one cardholder makes for a monthly statement, but also the basis – perhaps – for the calculation of loyalty rewards. And so forth.
  9. You understand that even in the theoretical distinction data/information there are a number of levels. That is why generally data and information are used as synonyms.
  10. Looking at the data we want to protect, we are focussing on data that can give the ABC Group an advantage on the competition. Running ahead of things that kind of data has a confidential nature. Examples of data that is “out-of-scope” is any data that is on the website, like general terms and conditions for customers, general terms and conditions for suppliers (procurement), investor information,...
  11. What is in scope? Creative ideas, like marketing campaigns, unique features to bolt on products or services, etc. Strategy, like what customers we target, how we want to service the customer in 3 years, etc.
  12. Who our customers are. If we gave them special conditions. If we gave them a compensation after a complaint.
  13. Cardholder data, transaction data, … and basically all information related to an identified or identiable natural person.
  14. Some data we legally have to protect, and for the other data we want to keep to ourselves because it is good for business.
  15. One important framework is the general data protection act (or in the future the general data protection regulation also known as GDPR). That legislation is all about “processing personal data”. We’ll go deeper into those two concepts, and build up from there to the other general concepts of that legislation.
  16. Personal data is defined as “any information relating to an identified or identifiable natural person”. Let us drill down on those components.
  17. Legal persons are not in scope of the Belgian Data Protection Act or the GDPR. As a little sidenote: some companies like hospitals, governments, banks insurances,…, even if the data protection legislation does not apply (or next to it), have to respect a (in principle contractual) duty of discretion. Also, the individuals related to corporate customers (the contacts, the legal representatives, the ultimate beneficial owners, the cardholders, the administrators,…) are very well in scope of the data protection legislation.
  18. The individual needs to be identified (that is quite easy) or identifiable. The identifiability is tricky, because in this day and age where computers can very quickly make a lot of calculations and combinations, an identity can sometimes be put on a data set where you would not have expected it.
  19. Fingerprints don’t have a person’s name on them, but the police can match them against a database.
  20. Your badge may not be personalised on the outside, but when it is used, the system registers “you” as badging scanner x, near door y at time z.
  21. Your picture may not be recognized by 6 billion + people on the planet, but facebook makes your friends tag you on it or google compares your facial features to determine with 99% certainty that it is you.
  22. In the data protection legislation the person identified is referred to as the data subject.
  23. The information that can be related to a person is only limited by the imagination.
  24. It can be as straightforward as your name, your eID number,
  25. your card number,
  26. or the way you use your card,
  27. your search results in google,
  28. your phone number,
  29. the geolocation from your cell phone,
  30. your heatbeat,
  31. the rythm with which you type texts on your keyboard,
  32. - sometimes just your shoe size can give away who you are.
  33. It is clear: personal data is very broad.
  34. The second component of the scope definition of the data protection legislation is “processing”; it is basically anything you do with data in an ordened way - on paper e.g. in a filing cabinet or automated by a computer (where the actual neat order is of less importance as the computer can overcome that with computing power).
  35. From collection… To deletion… And everything in between.
  36. Here the second player of the data protection act enters the stage: the data controller. He is the “entity” (in general a company) that processes the data and more importantly: determines what happens with the data and how?
  37. An example: the information in the application form, is it used only to assess the credit risk and determine the credit limit or is it also used for to send the new customer information about our services, marketing (upselling and cross-selling), partner mailings, …?
  38. The data protection legislation sets out quite a number of rather (legal) technical requirements. But it basically requires the data controller to be… in control of the data.
  39. The data controller must have a firm basis to collect and further process the personal data for certain purposes, for example - a legal requirment like performing anti-money laundering checks for banks, insurance companies, notaries public, etc. or sharing information on employment an make payments to the social security governmental bodies implicit consent to execute the contract, or even just to assess whether we want to enter into the employment, credit or insurance contract explicit consent to send email marketing, newsletters, etc.
  40. Being transparent about how the data controller processes personal data in a privacy statement is one way that makes that visible for the data subject and the outside world.
  41. The data controller must organise itself, which includes setting up technical measures and procedures to guard some important characteristics of the data.