SlideShare une entreprise Scribd logo
1  sur  39
Télécharger pour lire hors ligne
Privacy Shield – What You Need To Know About Storing EU Data | 1
Privacy Shield
What You Need to KnowAbout Storing EU Data
Privacy Shield – What You Need To Know About Storing EU Data | 2
Overview & Agenda
• Overview on global data protection
• The Past: EU-U.S. Safe Harbour
• The Present: EU-U.S. Privacy Shield
• How the Privacy Shield Differs from the Safe Harbour
• Deep Dive: The Framework
• Options to Prove You’re Compliant
• What is the Future?
• Q/A
Privacy Shield – What You Need To Know About Storing EU Data | 3
Overview on Global
Data Protection
Privacy Shield – What You Need To Know About Storing EU Data | 4
Overview
Regulate the collection, use, storage, disclosure,
and other processing of “personally identifiable
information” or “PII”
• Name and other “identifiers,” and any other data that can be
linked with the identified or identifiable person or device.
• Employees, consumers, contractors, corporate customer
contacts, supplier contacts, website visitors, business partner
contacts, end users, and other individuals.
Privacy Shield – What You Need To Know About Storing EU Data | 5
Overview
Two approaches to regulation globally:
• United States: Sector-specific (HIPAA/HITECH, GLBA/FCRA,
and the like) and data-specific (SSNs, bank account, credit/debit
card numbers, username/password to online account)
• European Union: Omnibus privacy laws applicable to all personal
data, regardless of sector, category of individual, or type of
personal data; local hurdles on collection and processing +
additional restrictions on cross-border transfers
• EU tends to lead the rest of the non-US world
Privacy Shield – What You Need To Know About Storing EU Data | 6
Some Examples
Privacy Shield – What You Need To Know About Storing EU Data | 6
• Business manifestations
• Cloud and sourcing
• Global HR databases
• Customer relationship management (CRM) applications
• Websites and mobile apps
• Mergers and acquisitions
Privacy Shield – What You Need To Know About Storing EU Data | 7
Some Examples
Privacy Shield – What You Need To Know About Storing EU Data | 7
• Compliance manifestations
• Whistleblower hotlines
• Email and internet monitoring
• Internal investigations
• E-discovery and legal demands
• Data security and breach notice
Privacy Shield – What You Need To Know About Storing EU Data | 8
1995 EC Data Protection Directive
(95/46/EC)
• Omnibus regulation for industry sectors
• Implemented by Member States into
national data protection laws
• Local compliance issues
• Cross-border data transfer restrictions
Privacy Shield – What You Need To Know About Storing EU Data | 9
The Past:
EU Safe Harbour
Privacy Shield – What You Need To Know About Storing EU Data | 10
Privacy Shield – What You Need To Know About Storing EU Data | 11Privacy Shield – What You Need To Know About Storing EU Data | 11
Privacy Shield – What You Need To Know About Storing EU Data | 12
Background on Schrems
Who is Max Schrems?
He is an Austrian privacy activist who campaigns against Facebook for
privacy violation, including its violations of European privacy laws and
alleged transfer of personal data to the US National Security
Agency (NSA) as part of the NSA's PRISM programme. He has founded
a group called Europe v Facebook and as of February 2015 has initiated
two lawsuits involving Facebook.
Privacy Shield – What You Need To Know About Storing EU Data | 13
Background on Schrems
How did the invalidation process get started?
• On 20 November 2014, Schrems said at a conference convened in
Brussels by the International Association of Privacy Professionals that
his group would go on a head-on collision with Safe Harbour, an E.U.-
U.S. agreement that allows over 3,000 U.S. companies, including
Google, Facebook, and Apple, to repatriate European personal data.
Schrems argues that in practice it does not give the consumer any
protection.[12]
Privacy Shield – What You Need To Know About Storing EU Data | 14
Background on Schrems
How did the invalidation process get started?
• In Schrems, the European Court of Justice (Court) invalidated the US-EU
Safe Harbor Privacy Arrangement (“Safe Harbor) on October 6, 2015
• Safe Harbor had served as the EC adequacy finding for the United
States for fifteen years
• The Court specified that Safe Harbor was not adequate because of the
apparent absence of sufficient protections within Safe Harbor against US
government surveillance and corresponding redress for EU citizens (not
“essentially equivalent”)
Privacy Shield – What You Need To Know About Storing EU Data | 15
Current Developments
• Initial Article 29 Working Party Opinion on Schrems (Oct 16, 2015):
– Transfers relying solely on Safe Harbor unlawful
– Model contracts and binding corporate rules can be used at present, although under
examination for concerns about government surveillance
– Collective action to be considered if no resolution on “Safe Harbor 2.0” by the end of
January 2016
• Various individual data protection authority opinions (e.g., German data protection
authorities, UK Information Commissioner, and the like).
• EU-US Privacy Shield (Safe Harbor 2.0) announced as agreed upon between the
European Commission and the US Department of Commerce and other
authorities on February 2, 2016 (ahead of WP meeting)
• Other developments (to be discussed after Privacy Shield overview)
Privacy Shield – What You Need To Know About Storing EU Data | 16
The Present: EU-U.S.
Privacy Shield
Privacy Shield – What You Need To Know About Storing EU Data | 17
"​The EU-U.S. Privacy Shield is
a tremendous victory for privacy,
individuals, and businesses on both
sides of the Atlantic."
- U.S. Secretary of Commerce Penny Pritzker
Privacy Shield – What You Need To Know About Storing EU Data | 18
EU-U.S. Privacy Shield
Privacy Shield – What You Need To Know About Storing EU Data | 18
Privacy Shield – What You Need To Know About Storing EU Data | 19
Why Was It Designed?
https://www.e-education.psu.edu/cloudGIS/node/91
• The EU-U.S. Privacy Shield Framework was designed by the U.S.
Department of Commerce and European Commission to provide companies
on both sides of the Atlantic with a mechanism to comply with EU data
protection requirements when transferring personal data from the European
Union to the United States in support of transatlantic commerce.
Privacy Shield – What You Need To Know About Storing EU Data | 20
Why Was It Designed?
https://www.e-education.psu.edu/cloudGIS/node/91
• The Privacy Shield Framework provides a set of robust and enforceable
protections for the personal data of EU individuals. The Framework provides
transparency regarding how participating companies use personal data,
strong U.S. government oversight, and increased cooperation with EU data
protection authorities (DPAs). The European Commission deemed the
Privacy Shield Framework adequate to enable data transfers under EU law.
Commerce will allow companies time to review the Framework and update
their compliance programs and then, on August 1, will begin accepting
certifications
• On February 29, 2016, the European Commission issued its draft decision
and the US documents for the EU-US Privacy Shield Arrangement.
Privacy Shield – What You Need To Know About Storing EU Data | 21
Why Was It Designed?
https://www.e-education.psu.edu/cloudGIS/node/91
• The US-issued Privacy Shield documents are:
– A commitment from the US Secretary of Commerce to devote all necessary
resources to adhere fully to the requirements of the Privacy Shield
– Twenty Two Privacy Shield Principles, along with Arbitration Procedures
– Letters from the Federal Trade Commission and the Department of
Transportation (commercial enforcement authority)
– Letters from the Office of the Director of National Intelligence (ODNI)
(surveillance law and policy), the Department of State (surveillance redress), and
the Department of Justice (criminal law enforcement law and policy)
Privacy Shield – What You Need To Know About Storing EU Data | 22
Why Was It Designed?
https://www.e-education.psu.edu/cloudGIS/node/91
• The European Commission is now (i) evaluating the non-binding views of
the Article 29 Working Party of Data Protection Authorities, the European
Parliament, the European Data Protection Supervisor, and (ii) consulting
with the Article 31 Member State Representatives
• Finalized and went into affect June 2016.
Privacy Shield – What You Need To Know About Storing EU Data | 23
Certification
https://www.e-education.psu.edu/cloudGIS/node/91
• Self-certify
• Department of Commerce
• Voluntary
• Eligible - Committed
Privacy Shield – What You Need To Know About Storing EU Data | 24
How the Privacy Shield
Differs from the Safe Harbour
Privacy Shield – What You Need To Know About Storing EU Data | 25
Enhancements from the Safe Harbour
https://www.e-education.psu.edu/cloudGIS/node/91
• Expanded privacy notices
• Strengthened standards on data transfers
• Reinforced certification/ recertification
• Clarified retention standards
• Commissioned recourse mechanisms
Privacy Shield – What You Need To Know About Storing EU Data | 26
Deep Dive: The
Framework
Privacy Shield – What You Need To Know About Storing EU Data | 27
Key Definitions and Clarifications
https://www.e-education.psu.edu/cloudGIS/node/91
• Personal and sensitive information
• Controllers vs. processors
• Publicly available data
• Exceptions
Privacy Shield – What You Need To Know About Storing EU Data | 27
Privacy Shield – What You Need To Know About Storing EU Data | 28
Notice
https://www.e-education.psu.edu/cloudGIS/node/91
• Required points of presentation
• Must detail:
– Commitment to the Privacy Shield
– Aspects of the privacy life cycle and individual rights
– Recourse, enforcement and liability
• Exceptions
Privacy Shield – What You Need To Know About Storing EU Data | 29
Choice
https://www.e-education.psu.edu/cloudGIS/node/91
• Required points of presentation
• Opt-out vs. opt-in mechanisms
• Exceptions
Privacy Shield – What You Need To Know About Storing EU Data | 29
Privacy Shield – What You Need To Know About Storing EU Data | 30
Accountability for Onward Transfer
https://www.e-education.psu.edu/cloudGIS/node/91
• Contracting with third parties acting as
controllers and agents
• Limiting transfers to specified purposes
• Noncompliance remediation and
processing cessation
• Exceptions
Privacy Shield – What You Need To Know About Storing EU Data | 31
Security
https://www.e-education.psu.edu/cloudGIS/node/91
Privacy Shield – What You Need To Know About Storing EU Data | 31
Privacy Shield – What You Need To Know About Storing EU Data | 32
Data Integrity and Purpose Limitation
https://www.e-education.psu.edu/cloudGIS/node/91
• Collection and processing limitation
• Data veracity controls
• Retention standards
Privacy Shield – What You Need To Know About Storing EU Data | 33
Access
https://www.e-education.psu.edu/cloudGIS/node/91
• Fielding requests for access to and the
correction and deletion of data
• Communications
• Facilitating requests
• Exceptions
Privacy Shield – What You Need To Know About Storing EU Data | 34
Recourse, Enforcement and Liability
https://www.e-education.psu.edu/cloudGIS/node/91
• Direct handling of individuals’ complaints
• Independent recourse mechanisms
• Cooperation with DPAs
• Arbitration
Privacy Shield – What You Need To Know About Storing EU Data | 35
Government Surveillance
https://www.e-education.psu.edu/cloudGIS/node/91
Privacy Shield – What You Need To Know About Storing EU Data | 35
Privacy Shield – What You Need To Know About Storing EU Data | 36
Options to Prove
You’re Compliant
Privacy Shield – What You Need To Know About Storing EU Data | 37
Certification and Periodic Assessment
https://www.e-education.psu.edu/cloudGIS/node/91
• Initiation
• Self-assessment vs. outside reviews
Privacy Shield – What You Need To Know About Storing EU Data | 38
What is the Future?
Privacy Shield – What You Need To Know About Storing EU Data | 39
• Pivoting on updates
• Challenges
• Iterations
• Verification
• Enterprise adoption
The Near Term and Long Term
Privacy Shield – What You Need To Know About Storing EU Data | 39

Contenu connexe

Tendances

General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
ETİD Kişisel Verilerin Korunması Kanunu Workshop Sunumu
ETİD Kişisel Verilerin Korunması Kanunu Workshop SunumuETİD Kişisel Verilerin Korunması Kanunu Workshop Sunumu
ETİD Kişisel Verilerin Korunması Kanunu Workshop SunumuETİD
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRIT Governance Ltd
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
General Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data TransfersGeneral Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data Transferspi
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Financial Poise
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Russell_Kennedy
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxRahulGarg294918
 
Privacy in India: Legal issues
Privacy in India: Legal issuesPrivacy in India: Legal issues
Privacy in India: Legal issuesSagar Rahurkar
 
ISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowPECB
 
Cyber security in power sector
Cyber security in power sectorCyber security in power sector
Cyber security in power sectorP K Agarwal
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_indiaAltacit Global
 
Data Security & Data Privacy: Data Anonymization
Data Security & Data Privacy: Data AnonymizationData Security & Data Privacy: Data Anonymization
Data Security & Data Privacy: Data AnonymizationPatric Dahse
 

Tendances (20)

General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
ETİD Kişisel Verilerin Korunması Kanunu Workshop Sunumu
ETİD Kişisel Verilerin Korunması Kanunu Workshop SunumuETİD Kişisel Verilerin Korunması Kanunu Workshop Sunumu
ETİD Kişisel Verilerin Korunması Kanunu Workshop Sunumu
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
General Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data TransfersGeneral Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data Transfers
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)Privacy and Data Protection Act 2014 (VIC)
Privacy and Data Protection Act 2014 (VIC)
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
 
Privacy in India: Legal issues
Privacy in India: Legal issuesPrivacy in India: Legal issues
Privacy in India: Legal issues
 
ISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to know
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
Cyber security in power sector
Cyber security in power sectorCyber security in power sector
Cyber security in power sector
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_india
 
Data Security & Data Privacy: Data Anonymization
Data Security & Data Privacy: Data AnonymizationData Security & Data Privacy: Data Anonymization
Data Security & Data Privacy: Data Anonymization
 
GDPR and Security.pdf
GDPR and Security.pdfGDPR and Security.pdf
GDPR and Security.pdf
 

En vedette

The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...
The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...
The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...Mark Aldrich
 
How to comply with Privacy Shield
How to comply with Privacy ShieldHow to comply with Privacy Shield
How to comply with Privacy Shieldtermsfeed
 
EU-U.S. Privacy Shield: Should You Sign Up?
EU-U.S. Privacy Shield: Should You Sign Up?EU-U.S. Privacy Shield: Should You Sign Up?
EU-U.S. Privacy Shield: Should You Sign Up?Winston & Strawn LLP
 
Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Schellman & Company
 
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...Schellman & Company
 
Determining Scope for PCI DSS Compliance
Determining Scope for PCI DSS ComplianceDetermining Scope for PCI DSS Compliance
Determining Scope for PCI DSS ComplianceSchellman & Company
 
Create Your Company Page
Create Your Company PageCreate Your Company Page
Create Your Company PageTariq Ahmad
 
[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to Know[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to KnowTrustArc
 
How to Use LinkedIn Company Pages & Groups
How to Use LinkedIn Company Pages & GroupsHow to Use LinkedIn Company Pages & Groups
How to Use LinkedIn Company Pages & GroupsHubSpot
 
How to stand out online
How to stand out onlineHow to stand out online
How to stand out onlineMars Dorian
 
How to Use Canva Like a Pro
How to Use Canva Like a ProHow to Use Canva Like a Pro
How to Use Canva Like a ProLillian DeJesus
 
Your Speech is Toxic
Your Speech is ToxicYour Speech is Toxic
Your Speech is ToxicChiara Ojeda
 
Great Speakers Tell Stories
Great Speakers Tell StoriesGreat Speakers Tell Stories
Great Speakers Tell StoriesSlides That Rock
 
15 Tips for Compelling Company Updates on LinkedIn
15 Tips for Compelling Company Updates on LinkedIn15 Tips for Compelling Company Updates on LinkedIn
15 Tips for Compelling Company Updates on LinkedInLinkedIn
 
SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...
SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...
SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...Empowered Presentations
 
What Makes Great Infographics
What Makes Great InfographicsWhat Makes Great Infographics
What Makes Great InfographicsSlideShare
 

En vedette (20)

The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...
The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...
The New Privacy Shield for Trans-Atlantic Data - Is the Shield Better, Differ...
 
How to comply with Privacy Shield
How to comply with Privacy ShieldHow to comply with Privacy Shield
How to comply with Privacy Shield
 
EU-U.S. Privacy Shield: Should You Sign Up?
EU-U.S. Privacy Shield: Should You Sign Up?EU-U.S. Privacy Shield: Should You Sign Up?
EU-U.S. Privacy Shield: Should You Sign Up?
 
Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1Everything You Need To Know About SOC 1
Everything You Need To Know About SOC 1
 
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
Work With Federal Agencies? Here's What You Should Know About FedRAMP Assessm...
 
Determining Scope for PCI DSS Compliance
Determining Scope for PCI DSS ComplianceDetermining Scope for PCI DSS Compliance
Determining Scope for PCI DSS Compliance
 
Create Your Company Page
Create Your Company PageCreate Your Company Page
Create Your Company Page
 
[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to Know[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to Know
 
How to Use LinkedIn Company Pages & Groups
How to Use LinkedIn Company Pages & GroupsHow to Use LinkedIn Company Pages & Groups
How to Use LinkedIn Company Pages & Groups
 
How to stand out online
How to stand out onlineHow to stand out online
How to stand out online
 
2012 and We're STILL Using PowerPoint Wrong
2012 and We're STILL Using PowerPoint Wrong2012 and We're STILL Using PowerPoint Wrong
2012 and We're STILL Using PowerPoint Wrong
 
How to Use Canva Like a Pro
How to Use Canva Like a ProHow to Use Canva Like a Pro
How to Use Canva Like a Pro
 
Your Speech is Toxic
Your Speech is ToxicYour Speech is Toxic
Your Speech is Toxic
 
Great Speakers Tell Stories
Great Speakers Tell StoriesGreat Speakers Tell Stories
Great Speakers Tell Stories
 
Slides That Rock
Slides That RockSlides That Rock
Slides That Rock
 
15 Tips for Compelling Company Updates on LinkedIn
15 Tips for Compelling Company Updates on LinkedIn15 Tips for Compelling Company Updates on LinkedIn
15 Tips for Compelling Company Updates on LinkedIn
 
SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...
SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...
SMOKE - The Convenient Truth [1st place Worlds Best Presentation Contest] by ...
 
SlideShare 101
SlideShare 101SlideShare 101
SlideShare 101
 
What Makes Great Infographics
What Makes Great InfographicsWhat Makes Great Infographics
What Makes Great Infographics
 
You Suck At PowerPoint!
You Suck At PowerPoint!You Suck At PowerPoint!
You Suck At PowerPoint!
 

Similaire à Privacy shield: What You Need To Know About Storing EU Data

EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementGACC_Midwest
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborGayle Gorvett
 
Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldParsons Behle & Latimer
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB
 
EU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTeEU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTeTrustArc
 
Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Agustin Argelich Casals
 
ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...Ulf Mattsson
 
TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...
TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...
TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...TrustArc
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...TrustArc
 
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...TrustArc
 
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...AltheimPrivacy
 
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...AltheimPrivacy
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyKate Chan
 
Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...
Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...
Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...AltheimPrivacy
 
Privacy Laws in Europe
Privacy Laws in EuropePrivacy Laws in Europe
Privacy Laws in EuropeMartyn Ripley
 
US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataMark Aldrich
 
Safe Harbor Webinar
Safe Harbor WebinarSafe Harbor Webinar
Safe Harbor WebinarEthisphere
 
The Patriot Act and Cloud Security - Busting the European FUD
The Patriot Act and Cloud Security - Busting the European FUDThe Patriot Act and Cloud Security - Busting the European FUD
The Patriot Act and Cloud Security - Busting the European FUDResilient Systems
 

Similaire à Privacy shield: What You Need To Know About Storing EU Data (20)

EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor Replacement
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe Harbor
 
Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy Shield
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?
 
EU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTeEU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTe
 
Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16
 
ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...
 
TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...
TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...
TrustArc Webinar: New EU-US Data Transfer Agreement - An Important Milestone ...
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
 
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
 
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
 
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
The EU Data Protection Reform's Impact on Cross Border E-discovery; updated h...
 
EU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection ChangesEU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection Changes
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...
Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...
Bridging U.S. Cross-Border Ediscovery Obligations and EU Data Protection Obli...
 
Privacy Laws in Europe
Privacy Laws in EuropePrivacy Laws in Europe
Privacy Laws in Europe
 
US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border Data
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
Safe Harbor Webinar
Safe Harbor WebinarSafe Harbor Webinar
Safe Harbor Webinar
 
The Patriot Act and Cloud Security - Busting the European FUD
The Patriot Act and Cloud Security - Busting the European FUDThe Patriot Act and Cloud Security - Busting the European FUD
The Patriot Act and Cloud Security - Busting the European FUD
 

Plus de Schellman & Company

Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018Schellman & Company
 
PA-DSS and Application Penetration Testing
PA-DSS and Application Penetration TestingPA-DSS and Application Penetration Testing
PA-DSS and Application Penetration TestingSchellman & Company
 
The CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & AttestationThe CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & AttestationSchellman & Company
 
STAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 CertifiedSTAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 CertifiedSchellman & Company
 
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018Schellman & Company
 
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST CertificationHitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST CertificationSchellman & Company
 
SOC 2: Build Trust and Confidence
SOC 2: Build Trust and ConfidenceSOC 2: Build Trust and Confidence
SOC 2: Build Trust and ConfidenceSchellman & Company
 
PCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key UpdatesPCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key UpdatesSchellman & Company
 
10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP Compliance10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP ComplianceSchellman & Company
 
Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?Schellman & Company
 

Plus de Schellman & Company (17)

Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018Privacy in the Cloud- Introduction to ISO 27018
Privacy in the Cloud- Introduction to ISO 27018
 
Demystifying the Cyber NISTs
Demystifying the Cyber NISTsDemystifying the Cyber NISTs
Demystifying the Cyber NISTs
 
PA-DSS and Application Penetration Testing
PA-DSS and Application Penetration TestingPA-DSS and Application Penetration Testing
PA-DSS and Application Penetration Testing
 
The CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & AttestationThe CSA STAR Program: Certification & Attestation
The CSA STAR Program: Certification & Attestation
 
Get Ready Now for HITRUST 2017
Get Ready Now for HITRUST 2017Get Ready Now for HITRUST 2017
Get Ready Now for HITRUST 2017
 
STAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 CertifiedSTAND OUT: Why You Should Become ISO 27001 Certified
STAND OUT: Why You Should Become ISO 27001 Certified
 
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
Locking Up Your Cloud Environment: An Introduction to ISO/IEC 27017 and 27018
 
SOC 2 and You
SOC 2 and YouSOC 2 and You
SOC 2 and You
 
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST CertificationHitrust: Navigating to 2017, Your Map to HITRUST Certification
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
 
CSA STAR Program
CSA STAR ProgramCSA STAR Program
CSA STAR Program
 
SOC 2: Build Trust and Confidence
SOC 2: Build Trust and ConfidenceSOC 2: Build Trust and Confidence
SOC 2: Build Trust and Confidence
 
SOC 1 Overview
SOC 1 OverviewSOC 1 Overview
SOC 1 Overview
 
12 Steps to Preparing for a QAR
12 Steps to Preparing for a QAR12 Steps to Preparing for a QAR
12 Steps to Preparing for a QAR
 
EPCS Overview
EPCS OverviewEPCS Overview
EPCS Overview
 
PCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key UpdatesPCI DSS 3.0 Overview and Key Updates
PCI DSS 3.0 Overview and Key Updates
 
10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP Compliance10 Steps Toward FedRAMP Compliance
10 Steps Toward FedRAMP Compliance
 
Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?Your've Been Hacked in Florida! Now What?
Your've Been Hacked in Florida! Now What?
 

Dernier

[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfOverkill Security
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 

Dernier (20)

[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 

Privacy shield: What You Need To Know About Storing EU Data

  • 1. Privacy Shield – What You Need To Know About Storing EU Data | 1 Privacy Shield What You Need to KnowAbout Storing EU Data
  • 2. Privacy Shield – What You Need To Know About Storing EU Data | 2 Overview & Agenda • Overview on global data protection • The Past: EU-U.S. Safe Harbour • The Present: EU-U.S. Privacy Shield • How the Privacy Shield Differs from the Safe Harbour • Deep Dive: The Framework • Options to Prove You’re Compliant • What is the Future? • Q/A
  • 3. Privacy Shield – What You Need To Know About Storing EU Data | 3 Overview on Global Data Protection
  • 4. Privacy Shield – What You Need To Know About Storing EU Data | 4 Overview Regulate the collection, use, storage, disclosure, and other processing of “personally identifiable information” or “PII” • Name and other “identifiers,” and any other data that can be linked with the identified or identifiable person or device. • Employees, consumers, contractors, corporate customer contacts, supplier contacts, website visitors, business partner contacts, end users, and other individuals.
  • 5. Privacy Shield – What You Need To Know About Storing EU Data | 5 Overview Two approaches to regulation globally: • United States: Sector-specific (HIPAA/HITECH, GLBA/FCRA, and the like) and data-specific (SSNs, bank account, credit/debit card numbers, username/password to online account) • European Union: Omnibus privacy laws applicable to all personal data, regardless of sector, category of individual, or type of personal data; local hurdles on collection and processing + additional restrictions on cross-border transfers • EU tends to lead the rest of the non-US world
  • 6. Privacy Shield – What You Need To Know About Storing EU Data | 6 Some Examples Privacy Shield – What You Need To Know About Storing EU Data | 6 • Business manifestations • Cloud and sourcing • Global HR databases • Customer relationship management (CRM) applications • Websites and mobile apps • Mergers and acquisitions
  • 7. Privacy Shield – What You Need To Know About Storing EU Data | 7 Some Examples Privacy Shield – What You Need To Know About Storing EU Data | 7 • Compliance manifestations • Whistleblower hotlines • Email and internet monitoring • Internal investigations • E-discovery and legal demands • Data security and breach notice
  • 8. Privacy Shield – What You Need To Know About Storing EU Data | 8 1995 EC Data Protection Directive (95/46/EC) • Omnibus regulation for industry sectors • Implemented by Member States into national data protection laws • Local compliance issues • Cross-border data transfer restrictions
  • 9. Privacy Shield – What You Need To Know About Storing EU Data | 9 The Past: EU Safe Harbour
  • 10. Privacy Shield – What You Need To Know About Storing EU Data | 10
  • 11. Privacy Shield – What You Need To Know About Storing EU Data | 11Privacy Shield – What You Need To Know About Storing EU Data | 11
  • 12. Privacy Shield – What You Need To Know About Storing EU Data | 12 Background on Schrems Who is Max Schrems? He is an Austrian privacy activist who campaigns against Facebook for privacy violation, including its violations of European privacy laws and alleged transfer of personal data to the US National Security Agency (NSA) as part of the NSA's PRISM programme. He has founded a group called Europe v Facebook and as of February 2015 has initiated two lawsuits involving Facebook.
  • 13. Privacy Shield – What You Need To Know About Storing EU Data | 13 Background on Schrems How did the invalidation process get started? • On 20 November 2014, Schrems said at a conference convened in Brussels by the International Association of Privacy Professionals that his group would go on a head-on collision with Safe Harbour, an E.U.- U.S. agreement that allows over 3,000 U.S. companies, including Google, Facebook, and Apple, to repatriate European personal data. Schrems argues that in practice it does not give the consumer any protection.[12]
  • 14. Privacy Shield – What You Need To Know About Storing EU Data | 14 Background on Schrems How did the invalidation process get started? • In Schrems, the European Court of Justice (Court) invalidated the US-EU Safe Harbor Privacy Arrangement (“Safe Harbor) on October 6, 2015 • Safe Harbor had served as the EC adequacy finding for the United States for fifteen years • The Court specified that Safe Harbor was not adequate because of the apparent absence of sufficient protections within Safe Harbor against US government surveillance and corresponding redress for EU citizens (not “essentially equivalent”)
  • 15. Privacy Shield – What You Need To Know About Storing EU Data | 15 Current Developments • Initial Article 29 Working Party Opinion on Schrems (Oct 16, 2015): – Transfers relying solely on Safe Harbor unlawful – Model contracts and binding corporate rules can be used at present, although under examination for concerns about government surveillance – Collective action to be considered if no resolution on “Safe Harbor 2.0” by the end of January 2016 • Various individual data protection authority opinions (e.g., German data protection authorities, UK Information Commissioner, and the like). • EU-US Privacy Shield (Safe Harbor 2.0) announced as agreed upon between the European Commission and the US Department of Commerce and other authorities on February 2, 2016 (ahead of WP meeting) • Other developments (to be discussed after Privacy Shield overview)
  • 16. Privacy Shield – What You Need To Know About Storing EU Data | 16 The Present: EU-U.S. Privacy Shield
  • 17. Privacy Shield – What You Need To Know About Storing EU Data | 17 "​The EU-U.S. Privacy Shield is a tremendous victory for privacy, individuals, and businesses on both sides of the Atlantic." - U.S. Secretary of Commerce Penny Pritzker
  • 18. Privacy Shield – What You Need To Know About Storing EU Data | 18 EU-U.S. Privacy Shield Privacy Shield – What You Need To Know About Storing EU Data | 18
  • 19. Privacy Shield – What You Need To Know About Storing EU Data | 19 Why Was It Designed? https://www.e-education.psu.edu/cloudGIS/node/91 • The EU-U.S. Privacy Shield Framework was designed by the U.S. Department of Commerce and European Commission to provide companies on both sides of the Atlantic with a mechanism to comply with EU data protection requirements when transferring personal data from the European Union to the United States in support of transatlantic commerce.
  • 20. Privacy Shield – What You Need To Know About Storing EU Data | 20 Why Was It Designed? https://www.e-education.psu.edu/cloudGIS/node/91 • The Privacy Shield Framework provides a set of robust and enforceable protections for the personal data of EU individuals. The Framework provides transparency regarding how participating companies use personal data, strong U.S. government oversight, and increased cooperation with EU data protection authorities (DPAs). The European Commission deemed the Privacy Shield Framework adequate to enable data transfers under EU law. Commerce will allow companies time to review the Framework and update their compliance programs and then, on August 1, will begin accepting certifications • On February 29, 2016, the European Commission issued its draft decision and the US documents for the EU-US Privacy Shield Arrangement.
  • 21. Privacy Shield – What You Need To Know About Storing EU Data | 21 Why Was It Designed? https://www.e-education.psu.edu/cloudGIS/node/91 • The US-issued Privacy Shield documents are: – A commitment from the US Secretary of Commerce to devote all necessary resources to adhere fully to the requirements of the Privacy Shield – Twenty Two Privacy Shield Principles, along with Arbitration Procedures – Letters from the Federal Trade Commission and the Department of Transportation (commercial enforcement authority) – Letters from the Office of the Director of National Intelligence (ODNI) (surveillance law and policy), the Department of State (surveillance redress), and the Department of Justice (criminal law enforcement law and policy)
  • 22. Privacy Shield – What You Need To Know About Storing EU Data | 22 Why Was It Designed? https://www.e-education.psu.edu/cloudGIS/node/91 • The European Commission is now (i) evaluating the non-binding views of the Article 29 Working Party of Data Protection Authorities, the European Parliament, the European Data Protection Supervisor, and (ii) consulting with the Article 31 Member State Representatives • Finalized and went into affect June 2016.
  • 23. Privacy Shield – What You Need To Know About Storing EU Data | 23 Certification https://www.e-education.psu.edu/cloudGIS/node/91 • Self-certify • Department of Commerce • Voluntary • Eligible - Committed
  • 24. Privacy Shield – What You Need To Know About Storing EU Data | 24 How the Privacy Shield Differs from the Safe Harbour
  • 25. Privacy Shield – What You Need To Know About Storing EU Data | 25 Enhancements from the Safe Harbour https://www.e-education.psu.edu/cloudGIS/node/91 • Expanded privacy notices • Strengthened standards on data transfers • Reinforced certification/ recertification • Clarified retention standards • Commissioned recourse mechanisms
  • 26. Privacy Shield – What You Need To Know About Storing EU Data | 26 Deep Dive: The Framework
  • 27. Privacy Shield – What You Need To Know About Storing EU Data | 27 Key Definitions and Clarifications https://www.e-education.psu.edu/cloudGIS/node/91 • Personal and sensitive information • Controllers vs. processors • Publicly available data • Exceptions Privacy Shield – What You Need To Know About Storing EU Data | 27
  • 28. Privacy Shield – What You Need To Know About Storing EU Data | 28 Notice https://www.e-education.psu.edu/cloudGIS/node/91 • Required points of presentation • Must detail: – Commitment to the Privacy Shield – Aspects of the privacy life cycle and individual rights – Recourse, enforcement and liability • Exceptions
  • 29. Privacy Shield – What You Need To Know About Storing EU Data | 29 Choice https://www.e-education.psu.edu/cloudGIS/node/91 • Required points of presentation • Opt-out vs. opt-in mechanisms • Exceptions Privacy Shield – What You Need To Know About Storing EU Data | 29
  • 30. Privacy Shield – What You Need To Know About Storing EU Data | 30 Accountability for Onward Transfer https://www.e-education.psu.edu/cloudGIS/node/91 • Contracting with third parties acting as controllers and agents • Limiting transfers to specified purposes • Noncompliance remediation and processing cessation • Exceptions
  • 31. Privacy Shield – What You Need To Know About Storing EU Data | 31 Security https://www.e-education.psu.edu/cloudGIS/node/91 Privacy Shield – What You Need To Know About Storing EU Data | 31
  • 32. Privacy Shield – What You Need To Know About Storing EU Data | 32 Data Integrity and Purpose Limitation https://www.e-education.psu.edu/cloudGIS/node/91 • Collection and processing limitation • Data veracity controls • Retention standards
  • 33. Privacy Shield – What You Need To Know About Storing EU Data | 33 Access https://www.e-education.psu.edu/cloudGIS/node/91 • Fielding requests for access to and the correction and deletion of data • Communications • Facilitating requests • Exceptions
  • 34. Privacy Shield – What You Need To Know About Storing EU Data | 34 Recourse, Enforcement and Liability https://www.e-education.psu.edu/cloudGIS/node/91 • Direct handling of individuals’ complaints • Independent recourse mechanisms • Cooperation with DPAs • Arbitration
  • 35. Privacy Shield – What You Need To Know About Storing EU Data | 35 Government Surveillance https://www.e-education.psu.edu/cloudGIS/node/91 Privacy Shield – What You Need To Know About Storing EU Data | 35
  • 36. Privacy Shield – What You Need To Know About Storing EU Data | 36 Options to Prove You’re Compliant
  • 37. Privacy Shield – What You Need To Know About Storing EU Data | 37 Certification and Periodic Assessment https://www.e-education.psu.edu/cloudGIS/node/91 • Initiation • Self-assessment vs. outside reviews
  • 38. Privacy Shield – What You Need To Know About Storing EU Data | 38 What is the Future?
  • 39. Privacy Shield – What You Need To Know About Storing EU Data | 39 • Pivoting on updates • Challenges • Iterations • Verification • Enterprise adoption The Near Term and Long Term Privacy Shield – What You Need To Know About Storing EU Data | 39