SlideShare une entreprise Scribd logo
1  sur  30
Télécharger pour lire hors ligne
1
vPrivacy Insight Series v
What Does the Proposed EU
Regulation Mean for Business
September 16, 2015
2
vPrivacy Insight Series
Today’s Speakers
Dennis Dayman,
Chief Privacy and
Security Officer,
Return Path Inc.
Dr Kai Westerwelle,
Partner,
Taylor Wessing
Mr Andrea Glorioso,
Counselor, Digital Economy /
Cyber Delegation of the
European Union to the USA
Eleanor Treharne-Jones,
Director, EMEA & Global
Communications, TRUSTe
3
vPrivacy Insight Series
Today’s Agenda
• Welcome & Introductions Eleanor Treharne-Jones
• Overview of the Main Changes in the Mr Andrea Glorioso
General Data Protection Regulation
• Key Areas in the Regulation - Dr Kai Westerwelle
Legal perspective and Impact on Business
• Actions to Prepare for the GDPR Dennis Dayman
• Q&A All
4
vPrivacy Insight Series v
The General Data Protection
Regulation (GDPR) – Overview of
the main changes
Mr Andrea Glorioso, Counselor, Digital Economy / Cyber Delegation
of the European Union to the USA
5
vPrivacy Insight Series
The GDPR: timeline
• January 2012: proposal of the European Commission
(draft Regulation + draft Directive on the exchange of
personal data for police and judicial cooperation)
• March 2014: the European Parliament adopts its "first
reading" position
• June 2015: the Council of the European Union adopts its
"general approach"
• July 2015 / ongoing: "trialogues" among the European
Commission, the European Parliament and the Council of
the European Union
• Expected adoption: end of 2015 / beginning of 2016?
6
vPrivacy Insight Series
The GDPR: what doesn't change
• The core legal concepts (e.g. definition of "personal data",
"data subject", "data controller", "data processor") do not
massively change compared to the main existing EU
legislation (1995 Directive)
• You still need a "legitimate basis" to process personal
data
• The objective remains the same: minimize differences of
legal treatment among EU Member States in order to
safeguard the internal / common market and ensure a
coherent (and high) level of protection of privacy and
personal data across the European Union
• Extra-EU data transfers still need a legal basis to take
place
7
vPrivacy Insight Series
The GDPR: main changes
• It's a Regulation, not a Directive: no need for Member
States to "transpose" it in their national legal systems
• "One-stop shop" system: organizations operating in
multiple Member States are supposed to interact only with
the Data Protection Authority in their "main place of
establishment"
• "Consistency mechanism": the "main" Data Protection
Authority is responsible for interacting with other Member
States' DPAs to ensure coherency and avoid multiple,
contradicting decisions
8
vPrivacy Insight Series
The GDPR: main changes
• "Information notices" will become much more detailed and
will have to be in an "intelligible form, using clear and
plain language, and adapted to the data subject".
• "Data processors" (e.g. sub-contractors to the data
controllers) are now subject to much stricter controls,
responsibilities and potential penalties.
• Principle of "accountability": data controllers / processors
must demonstrate existence of appropriate internal and
external processes, control systems, auditing checks,
impact assessment procedures and (in some cases)
appoint a Data Protection Officer.
• "Privacy by design" and "privacy by default"
9
vPrivacy Insight Series
The GDPR: main changes
• Certain "data processing" operations are now more strictly
regulated
• E.g. "profiling" which requires explicit consent when
performed on "sensitive data"
• Obligation to notify breaches that lead to the loss or
unauthorized dissemination of personal data
• Jurisdictional scope of application of the GDPR is now
broader: new rules apply also to organizations which are
based outside the EU but are offering goods and services
to EU residents or "monitor the behavior" of EU residents
• Penalties will in general be stiffer: maximum of 2-5% of
the global turnover of a company, or EUR 1 Million,
whichever is higher
10
vPrivacy Insight Series
The GDPR: the end of the Internet?
• The GDPR raises the bar of privacy / personal data
protection
• The rules are non-discriminatory: non-EU companies are
not penalized compared to EU companies
• Is this the much needed incentive for "data hygiene"
within data-intensive companies (e.g. nowadays, all
companies)?
11
vPrivacy Insight Series
EU-US data transfers
• Umbrella agreement (exchange of data for law
enforcement purposes): agreement reached on
September 8, waiting for "Judicial Redress Act" to be
adopted in the U.S.
• Safe Harbor discussions: final details on "national security
exemption" and "onward transfers", but overall agreement
on the 13 Recommendations of the European
Commission
• Extra-EU transfers of non-personal data was and is still
valid in principle!
• Safe Harbor is not the only mechanism: list of "legitimate
bases" for transfers (e.g. consent, performance of
contract), Binding Corporate Rules, standard contractual
clauses
12
vPrivacy Insight Series
More information
• General information: http://ec.europa.eu/justice/data-
protection/
• Supporting documents (fact sheets, background studies,
surveys): http://ec.europa.eu/justice/data-
protection/document/index_en.htm
• Extra-EU data transfers: http://ec.europa.eu/justice/data-
protection/international-transfers/index_en.htm
• Step-by-step timeline: http://eur-
lex.europa.eu/procedure/EN/201286
13
vPrivacy Insight Series v
Dr Kai Westerwelle, Partner Taylor Wessing (US) Inc.
Key Areas in the Regulation
Legal perspective and impact on business
14
vPrivacy Insight Series
Harmonization
• Actual
 European privacy laws based on EU DP Directive (to be transferred into local law)
 Result: different privacy laws in all European States (even within the states)
 Result: different levels of data protection (UK vs. France vs. Germany)
 Result: different regulatory requirements (e.g.: applications / registrations)
 Result: data protection officers only in some Member States
• Business Impact
 European roll-out difficult, time consuming, and cost intensive
 Idea: compliance with the strictest regime and roll out to “lower levels” (pyramid)
 Highest level might not be required and is costly
 Remaining uncertainties
15
vPrivacy Insight Series
Harmonization
• Future
 Regulation should create more harmonization (no transfer into local law)
 Result: the same law in all European states
 Result: the same regulatory requirements (e.g.: applications / registrations)
 But: room for interpretation by local authorities ?
• Business Impact
 European roll-out easy as one-size fits all
 One-stop shopping possible
 Compliance with European law much less costly
 Substantial business advantage (for EU and non-EU entities)
16
vPrivacy Insight Series
Harmonization
• Level of data protection
 Regulation creates the same level of data protection in all Member States
 For most European countries: stricter data protection rules
 For some European countries (e.g. Germany): lower standard
 Again: room for interpretation by local authorities ?
• Business Impact
 Changes required if compliant with lower level (“upgrade” DP level)
 Review and amend data protection policies
 Review and amend data processing agreements
 Install required positions (data protection officer ?)
 Establish required data protection measures (e.g. TOMs / certificats)
17
vPrivacy Insight Series
Applicability
• To non-EU companies
 Non-EU company offering goods or services to an EU data subject
 Non-EU company monitoring EU data subjects
 Unclear: applicable only to data controllers or also to data processors
• Direct relation
 Companies having their seat outside the EU must name a contact person within the EU
 Direct claims of EU data subjects in the US (umbrella agreement and US transfer)
18
vPrivacy Insight Series
No Changes
• Prohibition with exemption
 Collection and processing of personal data forbidden unless permitted
 Legitimate basis for processing required (statutory exemptions or consent)
• Group privilege
 One of the most important issues in privacy
 No exemption for a data transfer to group companies (HR, group services)
 Every data transfer within the group is a transfer to a third party
 Consequence: HR centralization, group services, etc. are an issue
 Exemption has been highly discussed, seems not to be in the actual draft
 Business impact: no facilitation – difficult status remains
19
vPrivacy Insight Series
Minor Changes
• Commissioned data processing
 Most important for any sort of outsourcing, cloud computing, services
 The legal concept (no transfer to a third party or general allowance) will not change
 Definition of “controller” and “processor” remain about the same
 Obligations for “Data Processors” will be stricter (control and penalties, liability)
 For Germany substantial change: limitation to the EU / EWR would be erased
• Business Impact
 Amendment to the actual processes
 For Germany: major facilitation of all outsourcing processes !
20
vPrivacy Insight Series
Major Changes
• Right to erasure of personal data / “Right to be Forgotten”
 Data subjects have far-reaching rights to erasure of their data
 “Right to be Forgotten”
 Already somehow in place (Google Spain)
 Additionally possible research and clean-up obligation of first publisher
 Business impact: technical requirements to safeguard process (technically difficult)
• Right to data transfer
 Data subjects have a right to request data transfer to another service provider
 Practical impact
 Impact on business set-up and terms
 Business impact: data might become less valuable
21
vPrivacy Insight Series
Major Changes
• Data Protection Authorities
 One-stop shopping: interaction between the authorities in the Member States
 Main data protection authority clarifies and aligns decisions
 Lead authority in case of establishments in different states (main establishment)
 “Work behind the scenes”
• Business Impact
 Enormous business impact
 Facilitation of processes (multi-jurisdictional projects)
 Hopefully: speed-up international processes
 May lead to substantial savings for companies dealing with international projects
22
vPrivacy Insight Series
Major Changes
• Data Protection Officer
 New concept to many Member States
 Influenced by the strict German data protection law but higher level (50)
 Might also have labor law implications
 Needs awareness and implementation in company structure
• Certificates (on Technical and Organizational Measures)
 Data protection certificates, seals, and marks (unclear relation to ASA or ISO)
 “One-stop approach” applies
 Supports outsourcing processes (audit requirements)
 Particularly supportive to data transfer to non-EU/EEA countries and cloud services
 High business impact: enabling / savings / selling advantage / customer requirements
23
vPrivacy Insight Series
Data Transfer to non-EU Countries
• No change
 Remains generally forbidden
 Unless “adequate level of data protection”
• Exceptions
 Consent of data subject
 Binding Corporate Rules
 EU Model Clauses (any changes ?)
 USA: Safe Harbor (important for US companies: new umbrella agreement)
 New: Data Protection Certificates
24
vPrivacy Insight Series v
Dennis Dayman, Chief Privacy and Security Officer, Return Path Inc.
Actions to Prepare for the GDPR -
Key Take-Aways
25
vPrivacy Insight Series
• Privacy Policies
• Multiple policies for different product lines
• https://returnpath.com/privacy-policy/
• Required languages for partners or 3rd party developers
• TRUSTe
• Auditor
• Mediator
• Easy to read
• Smaller sections
• Hyper-transparent
• Express Opt-in model
Actions to prepare for the GDPR
26
vPrivacy Insight Series
• Privacy by Design
• Taken steps to make sure that our systems and processes,
particularly new ones, deliver data protection compliance as a
matter of course.
• Involved development and program staff
• Reviewing and classify the personal data we hold and why we hold it
to ensure that we can meet the requirement for ‘data minimization’
• Privacy impact assessments
• Performing them on new/old products
Actions to prepare for the GDPR
27
vPrivacy Insight Series
• Consent, Control and insight
• Give to visitors and customers 100% control over data / accountability
• Security
• SSAE16 and ISO 27001 audit(s)
• Access limitations/security account based roles/2Fa/OKTA
• Breach management
• Response plan(s)
• Staff
• Education/Certification
• Localization
• Considering EU Data Centre’s
• Admin staff in local countries.
• Corporate data handling directives
• Data treasure maps
• Centralized record of authority which allows us to programmatically manage and perform
compliance on how data is used in the org
Actions to prepare for the GDPR
28
vPrivacy Insight Series v
Questions?
29
vPrivacy Insight Series v
Andrea Glorioso andrea.glorioso@eeas.europa.eu
Kai Westerwelle k.westerwelle@taylorwessing.com
Dennis Dayman @ddayman
Eleanor Treharne-Jones eleanor@truste.com
Contacts
30
vPrivacy Insight Series v
Don’t miss the next webinar in the Series – “Building an Effective
Privacy Program – Six Practical Steps” on September 24th
See http://www.truste.com/insightseries for details of future
webinars and recordings.
Thank You!

Contenu connexe

Tendances

Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protectionMRS
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Meteringnuances
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationGhostery, Inc.
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpJason Lackey
 
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...TrustArc
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?David Erdos
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection RegulationSabrina Kirrane
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance Tom Haynes
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
GDPR: More reasons for information security
GDPR: More reasons for information securityGDPR: More reasons for information security
GDPR: More reasons for information securityJisc
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPRJessvin Thomas
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findwise
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...Exove
 

Tendances (20)

Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Metering
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
GDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can HelpGDPR and NIS Compliance - How HyTrust Can Help
GDPR and NIS Compliance - How HyTrust Can Help
 
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
Interoperable Solutions for Cross Border Data Transfers – APEC, CBPR, BCR fro...
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
GDPR: More reasons for information security
GDPR: More reasons for information securityGDPR: More reasons for information security
GDPR: More reasons for information security
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 

En vedette

How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
How Good Privacy Practices can help prepare for a Data Breach from TRUSTe How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
How Good Privacy Practices can help prepare for a Data Breach from TRUSTe TrustArc
 
Building an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTeBuilding an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTeTrustArc
 
Webinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTe
Webinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTeWebinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTe
Webinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTeTrustArc
 
EU Safe Harbor – What Now?
EU Safe Harbor – What Now?EU Safe Harbor – What Now?
EU Safe Harbor – What Now?TrustArc
 
[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to Know[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to KnowTrustArc
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPRTripwire
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Meteringnuances
 
Dgpr media strategy analysis 2015 challenges and responses
Dgpr media strategy analysis 2015  challenges and responsesDgpr media strategy analysis 2015  challenges and responses
Dgpr media strategy analysis 2015 challenges and responsesbaglol
 
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014Arjen Noordzij
 

En vedette (11)

How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
How Good Privacy Practices can help prepare for a Data Breach from TRUSTe How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
 
Building an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTeBuilding an Effective Data Privacy Program – 6 Steps from TRUSTe
Building an Effective Data Privacy Program – 6 Steps from TRUSTe
 
Webinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTe
Webinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTeWebinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTe
Webinar on New DAA Guidelines for Ads Compliance in 2016 from TRUSTe
 
EU Safe Harbor – What Now?
EU Safe Harbor – What Now?EU Safe Harbor – What Now?
EU Safe Harbor – What Now?
 
[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to Know[Webinar Slides] Privacy Shield is Here – What You Need to Know
[Webinar Slides] Privacy Shield is Here – What You Need to Know
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPR
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
Improving the shelf life of sweetpotato roots in the market and household lev...
Improving the shelf life of sweetpotato roots in the market and household lev...Improving the shelf life of sweetpotato roots in the market and household lev...
Improving the shelf life of sweetpotato roots in the market and household lev...
 
Quick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart MeteringQuick Guide: EU General Data Protection Regulation and Smart Metering
Quick Guide: EU General Data Protection Regulation and Smart Metering
 
Dgpr media strategy analysis 2015 challenges and responses
Dgpr media strategy analysis 2015  challenges and responsesDgpr media strategy analysis 2015  challenges and responses
Dgpr media strategy analysis 2015 challenges and responses
 
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014
Privacy of patient data versus patient safety. HIMSS Europe, Nov 6, 2014
 

Similaire à What does the Proposed EU General Data Protection Regulation (GDPR) mean for Business – TRUSTe

Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Lumension
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberRachel Aldighieri
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberRachel Aldighieri
 
Presentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissiePresentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissieEuropadialoog
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India SadanandGahivare
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014Rachel Aldighieri
 
Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data OpportunityiCrossing
 
Wsgr eu data protection briefing march 20 2013 - final
Wsgr   eu data protection briefing march 20 2013 - finalWsgr   eu data protection briefing march 20 2013 - final
Wsgr eu data protection briefing march 20 2013 - finalValentin Korobkov
 
IT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestIT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestLilian Edwards
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORIKarel Holst
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIKarel Holst
 
Sirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & LearnSirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & LearnIgnitionOne
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesRob Blamires
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesRob Blamires
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPiwik PRO
 
Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKSally Hunt
 
Companies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsCompanies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsThe Economist Media Businesses
 

Similaire à What does the Proposed EU General Data Protection Regulation (GDPR) mean for Business – TRUSTe (20)

Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
Presentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissiePresentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese Commissie
 
DMA Scotland: Legal update
DMA Scotland: Legal updateDMA Scotland: Legal update
DMA Scotland: Legal update
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data Opportunity
 
Wsgr eu data protection briefing march 20 2013 - final
Wsgr   eu data protection briefing march 20 2013 - finalWsgr   eu data protection briefing march 20 2013 - final
Wsgr eu data protection briefing march 20 2013 - final
 
IT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestIT law : the middle kingdom between east and West
IT law : the middle kingdom between east and West
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
Sirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & LearnSirius Legal - IgnitionOne Lunch & Learn
Sirius Legal - IgnitionOne Lunch & Learn
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square Ventures
 
EU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square VenturesEU Privacy for US Businesses - Presentation to Union Square Ventures
EU Privacy for US Businesses - Presentation to Union Square Ventures
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital Setup
 
Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UK
 
Companies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsCompanies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next steps
 

Plus de TrustArc

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceTrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfTrustArc
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...TrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsTrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsTrustArc
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...TrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdfTrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceTrustArc
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023TrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining TrustTrustArc
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowTrustArc
 

Plus de TrustArc (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To Know
 

Dernier

It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsMichael W. Hawkins
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Delhi Call girls
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdftbatkhuu1
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaShree Krishna Exports
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒anilsa9823
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 

Dernier (20)

It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
HONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael HawkinsHONOR Veterans Event Keynote by Michael Hawkins
HONOR Veterans Event Keynote by Michael Hawkins
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdf
 
Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in India
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 

What does the Proposed EU General Data Protection Regulation (GDPR) mean for Business – TRUSTe

  • 1. 1 vPrivacy Insight Series v What Does the Proposed EU Regulation Mean for Business September 16, 2015
  • 2. 2 vPrivacy Insight Series Today’s Speakers Dennis Dayman, Chief Privacy and Security Officer, Return Path Inc. Dr Kai Westerwelle, Partner, Taylor Wessing Mr Andrea Glorioso, Counselor, Digital Economy / Cyber Delegation of the European Union to the USA Eleanor Treharne-Jones, Director, EMEA & Global Communications, TRUSTe
  • 3. 3 vPrivacy Insight Series Today’s Agenda • Welcome & Introductions Eleanor Treharne-Jones • Overview of the Main Changes in the Mr Andrea Glorioso General Data Protection Regulation • Key Areas in the Regulation - Dr Kai Westerwelle Legal perspective and Impact on Business • Actions to Prepare for the GDPR Dennis Dayman • Q&A All
  • 4. 4 vPrivacy Insight Series v The General Data Protection Regulation (GDPR) – Overview of the main changes Mr Andrea Glorioso, Counselor, Digital Economy / Cyber Delegation of the European Union to the USA
  • 5. 5 vPrivacy Insight Series The GDPR: timeline • January 2012: proposal of the European Commission (draft Regulation + draft Directive on the exchange of personal data for police and judicial cooperation) • March 2014: the European Parliament adopts its "first reading" position • June 2015: the Council of the European Union adopts its "general approach" • July 2015 / ongoing: "trialogues" among the European Commission, the European Parliament and the Council of the European Union • Expected adoption: end of 2015 / beginning of 2016?
  • 6. 6 vPrivacy Insight Series The GDPR: what doesn't change • The core legal concepts (e.g. definition of "personal data", "data subject", "data controller", "data processor") do not massively change compared to the main existing EU legislation (1995 Directive) • You still need a "legitimate basis" to process personal data • The objective remains the same: minimize differences of legal treatment among EU Member States in order to safeguard the internal / common market and ensure a coherent (and high) level of protection of privacy and personal data across the European Union • Extra-EU data transfers still need a legal basis to take place
  • 7. 7 vPrivacy Insight Series The GDPR: main changes • It's a Regulation, not a Directive: no need for Member States to "transpose" it in their national legal systems • "One-stop shop" system: organizations operating in multiple Member States are supposed to interact only with the Data Protection Authority in their "main place of establishment" • "Consistency mechanism": the "main" Data Protection Authority is responsible for interacting with other Member States' DPAs to ensure coherency and avoid multiple, contradicting decisions
  • 8. 8 vPrivacy Insight Series The GDPR: main changes • "Information notices" will become much more detailed and will have to be in an "intelligible form, using clear and plain language, and adapted to the data subject". • "Data processors" (e.g. sub-contractors to the data controllers) are now subject to much stricter controls, responsibilities and potential penalties. • Principle of "accountability": data controllers / processors must demonstrate existence of appropriate internal and external processes, control systems, auditing checks, impact assessment procedures and (in some cases) appoint a Data Protection Officer. • "Privacy by design" and "privacy by default"
  • 9. 9 vPrivacy Insight Series The GDPR: main changes • Certain "data processing" operations are now more strictly regulated • E.g. "profiling" which requires explicit consent when performed on "sensitive data" • Obligation to notify breaches that lead to the loss or unauthorized dissemination of personal data • Jurisdictional scope of application of the GDPR is now broader: new rules apply also to organizations which are based outside the EU but are offering goods and services to EU residents or "monitor the behavior" of EU residents • Penalties will in general be stiffer: maximum of 2-5% of the global turnover of a company, or EUR 1 Million, whichever is higher
  • 10. 10 vPrivacy Insight Series The GDPR: the end of the Internet? • The GDPR raises the bar of privacy / personal data protection • The rules are non-discriminatory: non-EU companies are not penalized compared to EU companies • Is this the much needed incentive for "data hygiene" within data-intensive companies (e.g. nowadays, all companies)?
  • 11. 11 vPrivacy Insight Series EU-US data transfers • Umbrella agreement (exchange of data for law enforcement purposes): agreement reached on September 8, waiting for "Judicial Redress Act" to be adopted in the U.S. • Safe Harbor discussions: final details on "national security exemption" and "onward transfers", but overall agreement on the 13 Recommendations of the European Commission • Extra-EU transfers of non-personal data was and is still valid in principle! • Safe Harbor is not the only mechanism: list of "legitimate bases" for transfers (e.g. consent, performance of contract), Binding Corporate Rules, standard contractual clauses
  • 12. 12 vPrivacy Insight Series More information • General information: http://ec.europa.eu/justice/data- protection/ • Supporting documents (fact sheets, background studies, surveys): http://ec.europa.eu/justice/data- protection/document/index_en.htm • Extra-EU data transfers: http://ec.europa.eu/justice/data- protection/international-transfers/index_en.htm • Step-by-step timeline: http://eur- lex.europa.eu/procedure/EN/201286
  • 13. 13 vPrivacy Insight Series v Dr Kai Westerwelle, Partner Taylor Wessing (US) Inc. Key Areas in the Regulation Legal perspective and impact on business
  • 14. 14 vPrivacy Insight Series Harmonization • Actual  European privacy laws based on EU DP Directive (to be transferred into local law)  Result: different privacy laws in all European States (even within the states)  Result: different levels of data protection (UK vs. France vs. Germany)  Result: different regulatory requirements (e.g.: applications / registrations)  Result: data protection officers only in some Member States • Business Impact  European roll-out difficult, time consuming, and cost intensive  Idea: compliance with the strictest regime and roll out to “lower levels” (pyramid)  Highest level might not be required and is costly  Remaining uncertainties
  • 15. 15 vPrivacy Insight Series Harmonization • Future  Regulation should create more harmonization (no transfer into local law)  Result: the same law in all European states  Result: the same regulatory requirements (e.g.: applications / registrations)  But: room for interpretation by local authorities ? • Business Impact  European roll-out easy as one-size fits all  One-stop shopping possible  Compliance with European law much less costly  Substantial business advantage (for EU and non-EU entities)
  • 16. 16 vPrivacy Insight Series Harmonization • Level of data protection  Regulation creates the same level of data protection in all Member States  For most European countries: stricter data protection rules  For some European countries (e.g. Germany): lower standard  Again: room for interpretation by local authorities ? • Business Impact  Changes required if compliant with lower level (“upgrade” DP level)  Review and amend data protection policies  Review and amend data processing agreements  Install required positions (data protection officer ?)  Establish required data protection measures (e.g. TOMs / certificats)
  • 17. 17 vPrivacy Insight Series Applicability • To non-EU companies  Non-EU company offering goods or services to an EU data subject  Non-EU company monitoring EU data subjects  Unclear: applicable only to data controllers or also to data processors • Direct relation  Companies having their seat outside the EU must name a contact person within the EU  Direct claims of EU data subjects in the US (umbrella agreement and US transfer)
  • 18. 18 vPrivacy Insight Series No Changes • Prohibition with exemption  Collection and processing of personal data forbidden unless permitted  Legitimate basis for processing required (statutory exemptions or consent) • Group privilege  One of the most important issues in privacy  No exemption for a data transfer to group companies (HR, group services)  Every data transfer within the group is a transfer to a third party  Consequence: HR centralization, group services, etc. are an issue  Exemption has been highly discussed, seems not to be in the actual draft  Business impact: no facilitation – difficult status remains
  • 19. 19 vPrivacy Insight Series Minor Changes • Commissioned data processing  Most important for any sort of outsourcing, cloud computing, services  The legal concept (no transfer to a third party or general allowance) will not change  Definition of “controller” and “processor” remain about the same  Obligations for “Data Processors” will be stricter (control and penalties, liability)  For Germany substantial change: limitation to the EU / EWR would be erased • Business Impact  Amendment to the actual processes  For Germany: major facilitation of all outsourcing processes !
  • 20. 20 vPrivacy Insight Series Major Changes • Right to erasure of personal data / “Right to be Forgotten”  Data subjects have far-reaching rights to erasure of their data  “Right to be Forgotten”  Already somehow in place (Google Spain)  Additionally possible research and clean-up obligation of first publisher  Business impact: technical requirements to safeguard process (technically difficult) • Right to data transfer  Data subjects have a right to request data transfer to another service provider  Practical impact  Impact on business set-up and terms  Business impact: data might become less valuable
  • 21. 21 vPrivacy Insight Series Major Changes • Data Protection Authorities  One-stop shopping: interaction between the authorities in the Member States  Main data protection authority clarifies and aligns decisions  Lead authority in case of establishments in different states (main establishment)  “Work behind the scenes” • Business Impact  Enormous business impact  Facilitation of processes (multi-jurisdictional projects)  Hopefully: speed-up international processes  May lead to substantial savings for companies dealing with international projects
  • 22. 22 vPrivacy Insight Series Major Changes • Data Protection Officer  New concept to many Member States  Influenced by the strict German data protection law but higher level (50)  Might also have labor law implications  Needs awareness and implementation in company structure • Certificates (on Technical and Organizational Measures)  Data protection certificates, seals, and marks (unclear relation to ASA or ISO)  “One-stop approach” applies  Supports outsourcing processes (audit requirements)  Particularly supportive to data transfer to non-EU/EEA countries and cloud services  High business impact: enabling / savings / selling advantage / customer requirements
  • 23. 23 vPrivacy Insight Series Data Transfer to non-EU Countries • No change  Remains generally forbidden  Unless “adequate level of data protection” • Exceptions  Consent of data subject  Binding Corporate Rules  EU Model Clauses (any changes ?)  USA: Safe Harbor (important for US companies: new umbrella agreement)  New: Data Protection Certificates
  • 24. 24 vPrivacy Insight Series v Dennis Dayman, Chief Privacy and Security Officer, Return Path Inc. Actions to Prepare for the GDPR - Key Take-Aways
  • 25. 25 vPrivacy Insight Series • Privacy Policies • Multiple policies for different product lines • https://returnpath.com/privacy-policy/ • Required languages for partners or 3rd party developers • TRUSTe • Auditor • Mediator • Easy to read • Smaller sections • Hyper-transparent • Express Opt-in model Actions to prepare for the GDPR
  • 26. 26 vPrivacy Insight Series • Privacy by Design • Taken steps to make sure that our systems and processes, particularly new ones, deliver data protection compliance as a matter of course. • Involved development and program staff • Reviewing and classify the personal data we hold and why we hold it to ensure that we can meet the requirement for ‘data minimization’ • Privacy impact assessments • Performing them on new/old products Actions to prepare for the GDPR
  • 27. 27 vPrivacy Insight Series • Consent, Control and insight • Give to visitors and customers 100% control over data / accountability • Security • SSAE16 and ISO 27001 audit(s) • Access limitations/security account based roles/2Fa/OKTA • Breach management • Response plan(s) • Staff • Education/Certification • Localization • Considering EU Data Centre’s • Admin staff in local countries. • Corporate data handling directives • Data treasure maps • Centralized record of authority which allows us to programmatically manage and perform compliance on how data is used in the org Actions to prepare for the GDPR
  • 29. 29 vPrivacy Insight Series v Andrea Glorioso andrea.glorioso@eeas.europa.eu Kai Westerwelle k.westerwelle@taylorwessing.com Dennis Dayman @ddayman Eleanor Treharne-Jones eleanor@truste.com Contacts
  • 30. 30 vPrivacy Insight Series v Don’t miss the next webinar in the Series – “Building an Effective Privacy Program – Six Practical Steps” on September 24th See http://www.truste.com/insightseries for details of future webinars and recordings. Thank You!