SlideShare une entreprise Scribd logo
1  sur  24
Why GDPR?
 The issues with how organisations manage data at
present
 What is GDPR and how will help protect
consumers?
 What do businesses need to know?
 4 steps to be GDPR compliant
Preparing for 25th May 2018
THE WORLD HAS CHANGED
Over 3 million
data records are lost or stolen
every day
Existing EU Directives are not enough to protect European Citizens
Data
Risks
Cloud-apps
Prospect
Data
Customer
Data
Marketing
Automation
Internal /
Employee
Records
Increased
Visibility /
Accessibility
Mobile
Workforce
Hackers
IoT
Suppliers
NEW RISKS
In 63% of all data breaches, third parties were implicated
 DropBox, SharePoint or Google Docs? -
 98% of cloud apps aren’t GDPR-ready
 IoT only complicates GDPR further
Source: http://www.jdsupra.com/legalnews/third-party-data-breaches-weakest-link-98330/
OVERVIEW OF EU GENERAL DATA PROTECTION
REGULATION
 General Data Protection Regulation – enforced by EU
 Expands on some parts of DPA/existing Directive;
creates other new requirements
 Determines how personal data should be processed
and used
 Comes into effect on 25 May 2018, regardless of
Brexit
What is GDPR?
SO WHAT?
 Impacts every data controller and processor dealing
with data on subjects in Europe
 79 times higher than previous fines
Potential fines of up to 4% of your organisation’s annual turnover or €20,000,000 – Whichever
is higher
Who? Means:
Data subject Any EU citizen who has entrusted a controller with
their personal data.
Customers, service users, employees
Data
controller
Who the data subject entrusts with their data.
Responsible for deciding how the data is handled.
Data
processor
Any entity that handles personal data on the data
controller's behalf.
What do businesses need to know?
What’s new?
 Expanded definition of “personal data”
 Transparency and consent
 Enhanced rights for data subjects
 Accountability
 Data protection by design
 Notifying subjects of data breaches
New rights you need to know
Rights
to
Be informed
Access
Rectification
Erasure
Restrict
Processsing
Data
Portability
Object
Personal data
Any form of automated data processing to analyse or predict:
 Performance at work
 Economic situation
 Health
 Personal preferences
 Reliability
 Behaviour
 Location
 Movements
Are you keeping, or planning to keep:
Personal or sensitive data such as
cookies, IP addresses, biometric data,
genetic data?
4 Requirements for Your Data Protection Policy
1) Legal basis for processing
2) Legitimate interests (if any)
3) Right to lodge complaint
4) How long data will be retained
Clear, concise and accessible
Consent
 Freely given, specific, informed and unambiguous
 Clear affirmative action
 Provided separately from other written agreements
 Verifiable
 As easily withdrawn as given
Hint!
Large and complex structured
organisations benefit from an
EQMS to manage policies and
procedures, approval workflows
and monitor compliance
activity.
Make employees accountable:
http://quality.eqms.co.uk/eqms
-datasheets-download
Get your policies and processes in order
Poor Passwords
Weak remote access
Unpatched flaws
Misconfigurations
Malicious Insider
http://www.computerworlduk.com/security/most-data-breaches-still-discovered-by-third-parties-3615783/
The average time between breach
and discovery is
188 DAYS
DATA BREACHES ARE USUALLY PREVENTABLE
Protect your reputation with proactive policies, employee training & robust systems
Notification of data breaches
Destroyed, lost, altered, disclosed to or accessed by
unauthorised people
Reported to:
 Supervisory authority
 Discrimination, reputational damage, financial loss,
confidentiality
 Individual(s) affected
 Same, but high risk
Report within 72 hours of breach
Accountability is key
Hint!
EQMS Workflow Manager
assigns responsibility and
manages incidents such as a
data breach through to
completion. Everyone knows
what they are doing, when.
Make employees accountable:
http://quality.eqms.co.uk/eqms
-software-demonstration
Accountability – Data protection by design
Must demonstrate compliance with GDPR - How?
 Policies and procedures (audits, HR policies)
 Staff training
 Pseudonymisation
 Data protection impact assessments
 Appointing data protection officer
Robust systems to protect employees and customers
Hint!
EQMS provides a robust
framework for managing
business processes. Manage
policies, assign responsibility
and use the audit trail function
to demonstrate compliance
activity.
Read more:
http://quality.eqms.co.uk/eqms
-software-demonstration
Enhanced rights for data subjects
Right to:
 Confirmation that data is being processed
 Receive data
 Rectify any inaccurate or incomplete data
 ‘Be forgotten’
 Restrict processing of data
 Obtain and re-use data for own purposes
Accountability is key
Example Timeline for GDPR Compliance Training
 Workshop with high interest / high power stakeholders:
 What data do we have?
 What data are we planning to have?
 How can we minimise risk? E.g. pseudonymisation.
 Make department managers accountable for the data they capture:
 Has each department manager completed a data protection impact assessment? (Use EQMS Audit
Manager & assign audit to be completed by each department manager.)
 Are the policies sufficient?
 Are controls in place to demonstrate opt-in?
 Do we need to get permission to continue using this data?
 Do we need a Data Protection Officer?
 Roll out training Train employees on the new GDPR requirements - EQMS Training Record Manager
 Employees aware & engaged with their GDPR requirements. (Use EQMS Training Manager training
matrix to easily manage which employees have outstanding training requriements)
Steps to getting GDPR-ready
ISO 27001 PROVIDES A FRAMEWORK FOR
GDPR COMPLIANCE
What might your business need to do?
Steps to compliance
 Review data protection policies
 Establish legal basis for processing
 Identify how to demonstrate compliance
 Consider whether to appoint DPO
1) Review policies
 Individuals told about right to object, at first communication
 Understanding of what constitutes “data breach” – more than loss of data
 Procedures for detecting, investigating and reporting breaches
 Insurance coverage in case of breach
2) Establish legal basis for processing
Be clear on grounds for lawful processing
If consent:
 Obtained correctly, as mentioned earlier
 Subjects informed of right to withdraw at any time, and given
simple methods to do so
3) Demonstrate compliance
New policies – data protection by design
Regular audits
Staff training
Pseudonymisation
Review and update existing information notices
4) Consider a data protection officer
Informs and advises on obligations
Monitors compliance – manages internal activities and audits, trains staff
First point of contact for supervisory authorities and data subjects
Compulsory that DPO:
 Reports to board/directors
 Independent, and not penalised for performing job
 Has resources to meet obligations
Can be existing employee as long as compatible and no conflict of interest
No qualifications, but should have professional experience and knowledge of law
25 May 2018
DOWNLOAD GDPR TOOLKIT
Q U A L I T Y . E Q M S . C O . U K / G D P R - G E N E R A L - D A T A - P R O T E C T I O N - R E G U L A T I O N - E U - T O O L K I T

Contenu connexe

Tendances

Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
Training privacy by design
Training privacy by designTraining privacy by design
Training privacy by designTommy Vandepitte
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxRahulGarg294918
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Benjamin Ang
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance PreparationLawPlus Ltd.
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Kimberly Simon MBA
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRRotary International
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacylegalPadmin
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data SecurityWilmerHale
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Complianceaccenture
 

Tendances (20)

Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Training privacy by design
Training privacy by designTraining privacy by design
Training privacy by design
 
GDPR
GDPRGDPR
GDPR
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR
GDPRGDPR
GDPR
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance Preparation
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 

Similaire à Why GDPR? 4 Steps to GDPR Compliance

Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessSirius
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPRNate Stockard
 
Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Gerson Trigueiros
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaperJim Wilson
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protectionMRS
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Per Norhammar
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
What is Information Governance
What is Information GovernanceWhat is Information Governance
What is Information GovernanceAtle Skjekkeland
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
DLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The ChallengesDLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The ChallengesNapier University
 
Setting the right GDPR priorities
Setting the right GDPR prioritiesSetting the right GDPR priorities
Setting the right GDPR prioritiesAlberto Canadè
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityEQS Group
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRzayadeen2003
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protectionmeritnorthwest
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Jonathan Chilton
 
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...David Kearney
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyRay ABOU
 

Similaire à Why GDPR? 4 Steps to GDPR Compliance (20)

Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)Eu data protection regulations (point-of-view)
Eu data protection regulations (point-of-view)
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?Will you be ready to comply with new EU Data Protection Regulation in time?
Will you be ready to comply with new EU Data Protection Regulation in time?
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
What is Information Governance
What is Information GovernanceWhat is Information Governance
What is Information Governance
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
DLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The ChallengesDLP: Monitoring Legal Obligations, Managing The Challenges
DLP: Monitoring Legal Obligations, Managing The Challenges
 
Setting the right GDPR priorities
Setting the right GDPR prioritiesSetting the right GDPR priorities
Setting the right GDPR priorities
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Merit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data ProtectionMerit Event - Understanding and Managing Data Protection
Merit Event - Understanding and Managing Data Protection
 
Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018 Wolters Kluwer GDPR Webinar 9 May 2018
Wolters Kluwer GDPR Webinar 9 May 2018
 
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 

Plus de Qualsys Ltd

Audits, inspections and reporting -
Audits, inspections and reporting - Audits, inspections and reporting -
Audits, inspections and reporting - Qualsys Ltd
 
Qualsys and sirus
Qualsys and sirus Qualsys and sirus
Qualsys and sirus Qualsys Ltd
 
How to Audit Leadership
How to Audit LeadershipHow to Audit Leadership
How to Audit LeadershipQualsys Ltd
 
Qualsys GXP presentation
Qualsys GXP  presentation Qualsys GXP  presentation
Qualsys GXP presentation Qualsys Ltd
 
APQP Training presentation
APQP Training  presentationAPQP Training  presentation
APQP Training presentationQualsys Ltd
 
As 9100 D QMS Training Materials
As 9100 D QMS Training Materials As 9100 D QMS Training Materials
As 9100 D QMS Training Materials Qualsys Ltd
 
Culture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training WorkshopCulture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training WorkshopQualsys Ltd
 
ISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management SoftwareISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management SoftwareQualsys Ltd
 
8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training 8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training Qualsys Ltd
 
Lean six sigma explained: Beginners training
Lean six sigma explained: Beginners trainingLean six sigma explained: Beginners training
Lean six sigma explained: Beginners trainingQualsys Ltd
 
Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study Qualsys Ltd
 
Best practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and SourcingBest practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and SourcingQualsys Ltd
 
ISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationQualsys Ltd
 
ISO 19011 Revision
ISO 19011 RevisionISO 19011 Revision
ISO 19011 RevisionQualsys Ltd
 
How to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance SoftwareHow to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance SoftwareQualsys Ltd
 
Embedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 FocusEmbedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 FocusQualsys Ltd
 
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...Qualsys Ltd
 
Equipment maintenance management: implementation
Equipment maintenance management: implementationEquipment maintenance management: implementation
Equipment maintenance management: implementationQualsys Ltd
 
Global Quality Survey Results 2016
Global Quality Survey Results 2016Global Quality Survey Results 2016
Global Quality Survey Results 2016Qualsys Ltd
 
Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015Qualsys Ltd
 

Plus de Qualsys Ltd (20)

Audits, inspections and reporting -
Audits, inspections and reporting - Audits, inspections and reporting -
Audits, inspections and reporting -
 
Qualsys and sirus
Qualsys and sirus Qualsys and sirus
Qualsys and sirus
 
How to Audit Leadership
How to Audit LeadershipHow to Audit Leadership
How to Audit Leadership
 
Qualsys GXP presentation
Qualsys GXP  presentation Qualsys GXP  presentation
Qualsys GXP presentation
 
APQP Training presentation
APQP Training  presentationAPQP Training  presentation
APQP Training presentation
 
As 9100 D QMS Training Materials
As 9100 D QMS Training Materials As 9100 D QMS Training Materials
As 9100 D QMS Training Materials
 
Culture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training WorkshopCulture of quality workshop - Qualsys Training Workshop
Culture of quality workshop - Qualsys Training Workshop
 
ISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management SoftwareISO 45001:2018 Health and Safety Management Software
ISO 45001:2018 Health and Safety Management Software
 
8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training 8D problem solving for NCR management: Beginners training
8D problem solving for NCR management: Beginners training
 
Lean six sigma explained: Beginners training
Lean six sigma explained: Beginners trainingLean six sigma explained: Beginners training
Lean six sigma explained: Beginners training
 
Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study Sodexo governance, risk and compliance software (GRC) case study
Sodexo governance, risk and compliance software (GRC) case study
 
Best practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and SourcingBest practice approach for PLM, Product Supply and Sourcing
Best practice approach for PLM, Product Supply and Sourcing
 
ISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentationISO 22301 leadership buy in presentation
ISO 22301 leadership buy in presentation
 
ISO 19011 Revision
ISO 19011 RevisionISO 19011 Revision
ISO 19011 Revision
 
How to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance SoftwareHow to Drive Engagement with Enterprise Compliance Software
How to Drive Engagement with Enterprise Compliance Software
 
Embedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 FocusEmbedding a culture of quality: ISO 9001:2015 Focus
Embedding a culture of quality: ISO 9001:2015 Focus
 
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
7 Step Guide To Successfully Managing a Change Project & Winning Stakeholders...
 
Equipment maintenance management: implementation
Equipment maintenance management: implementationEquipment maintenance management: implementation
Equipment maintenance management: implementation
 
Global Quality Survey Results 2016
Global Quality Survey Results 2016Global Quality Survey Results 2016
Global Quality Survey Results 2016
 
Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015Good Document Control Practices and Procedures: ISO 9001:2015
Good Document Control Practices and Procedures: ISO 9001:2015
 

Dernier

Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
A305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdfA305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdftbatkhuu1
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insightsseri bangash
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...Any kyc Account
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒anilsa9823
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 

Dernier (20)

Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
A305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdfA305_A2_file_Batkhuu progress report.pdf
A305_A2_file_Batkhuu progress report.pdf
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insights
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
KYC-Verified Accounts: Helping Companies Handle Challenging Regulatory Enviro...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒VIP Call Girls In Saharaganj ( Lucknow  ) 🔝 8923113531 🔝  Cash Payment (COD) 👒
VIP Call Girls In Saharaganj ( Lucknow ) 🔝 8923113531 🔝 Cash Payment (COD) 👒
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 

Why GDPR? 4 Steps to GDPR Compliance

  • 1. Why GDPR?  The issues with how organisations manage data at present  What is GDPR and how will help protect consumers?  What do businesses need to know?  4 steps to be GDPR compliant Preparing for 25th May 2018
  • 2. THE WORLD HAS CHANGED Over 3 million data records are lost or stolen every day Existing EU Directives are not enough to protect European Citizens
  • 3. Data Risks Cloud-apps Prospect Data Customer Data Marketing Automation Internal / Employee Records Increased Visibility / Accessibility Mobile Workforce Hackers IoT Suppliers NEW RISKS In 63% of all data breaches, third parties were implicated  DropBox, SharePoint or Google Docs? -  98% of cloud apps aren’t GDPR-ready  IoT only complicates GDPR further Source: http://www.jdsupra.com/legalnews/third-party-data-breaches-weakest-link-98330/
  • 4. OVERVIEW OF EU GENERAL DATA PROTECTION REGULATION  General Data Protection Regulation – enforced by EU  Expands on some parts of DPA/existing Directive; creates other new requirements  Determines how personal data should be processed and used  Comes into effect on 25 May 2018, regardless of Brexit What is GDPR?
  • 5. SO WHAT?  Impacts every data controller and processor dealing with data on subjects in Europe  79 times higher than previous fines Potential fines of up to 4% of your organisation’s annual turnover or €20,000,000 – Whichever is higher Who? Means: Data subject Any EU citizen who has entrusted a controller with their personal data. Customers, service users, employees Data controller Who the data subject entrusts with their data. Responsible for deciding how the data is handled. Data processor Any entity that handles personal data on the data controller's behalf.
  • 6. What do businesses need to know?
  • 7. What’s new?  Expanded definition of “personal data”  Transparency and consent  Enhanced rights for data subjects  Accountability  Data protection by design  Notifying subjects of data breaches New rights you need to know Rights to Be informed Access Rectification Erasure Restrict Processsing Data Portability Object
  • 8. Personal data Any form of automated data processing to analyse or predict:  Performance at work  Economic situation  Health  Personal preferences  Reliability  Behaviour  Location  Movements Are you keeping, or planning to keep: Personal or sensitive data such as cookies, IP addresses, biometric data, genetic data?
  • 9. 4 Requirements for Your Data Protection Policy 1) Legal basis for processing 2) Legitimate interests (if any) 3) Right to lodge complaint 4) How long data will be retained Clear, concise and accessible
  • 10. Consent  Freely given, specific, informed and unambiguous  Clear affirmative action  Provided separately from other written agreements  Verifiable  As easily withdrawn as given Hint! Large and complex structured organisations benefit from an EQMS to manage policies and procedures, approval workflows and monitor compliance activity. Make employees accountable: http://quality.eqms.co.uk/eqms -datasheets-download Get your policies and processes in order
  • 11. Poor Passwords Weak remote access Unpatched flaws Misconfigurations Malicious Insider http://www.computerworlduk.com/security/most-data-breaches-still-discovered-by-third-parties-3615783/ The average time between breach and discovery is 188 DAYS DATA BREACHES ARE USUALLY PREVENTABLE Protect your reputation with proactive policies, employee training & robust systems
  • 12. Notification of data breaches Destroyed, lost, altered, disclosed to or accessed by unauthorised people Reported to:  Supervisory authority  Discrimination, reputational damage, financial loss, confidentiality  Individual(s) affected  Same, but high risk Report within 72 hours of breach Accountability is key Hint! EQMS Workflow Manager assigns responsibility and manages incidents such as a data breach through to completion. Everyone knows what they are doing, when. Make employees accountable: http://quality.eqms.co.uk/eqms -software-demonstration
  • 13. Accountability – Data protection by design Must demonstrate compliance with GDPR - How?  Policies and procedures (audits, HR policies)  Staff training  Pseudonymisation  Data protection impact assessments  Appointing data protection officer Robust systems to protect employees and customers Hint! EQMS provides a robust framework for managing business processes. Manage policies, assign responsibility and use the audit trail function to demonstrate compliance activity. Read more: http://quality.eqms.co.uk/eqms -software-demonstration
  • 14. Enhanced rights for data subjects Right to:  Confirmation that data is being processed  Receive data  Rectify any inaccurate or incomplete data  ‘Be forgotten’  Restrict processing of data  Obtain and re-use data for own purposes Accountability is key
  • 15. Example Timeline for GDPR Compliance Training  Workshop with high interest / high power stakeholders:  What data do we have?  What data are we planning to have?  How can we minimise risk? E.g. pseudonymisation.  Make department managers accountable for the data they capture:  Has each department manager completed a data protection impact assessment? (Use EQMS Audit Manager & assign audit to be completed by each department manager.)  Are the policies sufficient?  Are controls in place to demonstrate opt-in?  Do we need to get permission to continue using this data?  Do we need a Data Protection Officer?  Roll out training Train employees on the new GDPR requirements - EQMS Training Record Manager  Employees aware & engaged with their GDPR requirements. (Use EQMS Training Manager training matrix to easily manage which employees have outstanding training requriements) Steps to getting GDPR-ready
  • 16. ISO 27001 PROVIDES A FRAMEWORK FOR GDPR COMPLIANCE
  • 17. What might your business need to do?
  • 18. Steps to compliance  Review data protection policies  Establish legal basis for processing  Identify how to demonstrate compliance  Consider whether to appoint DPO
  • 19. 1) Review policies  Individuals told about right to object, at first communication  Understanding of what constitutes “data breach” – more than loss of data  Procedures for detecting, investigating and reporting breaches  Insurance coverage in case of breach
  • 20. 2) Establish legal basis for processing Be clear on grounds for lawful processing If consent:  Obtained correctly, as mentioned earlier  Subjects informed of right to withdraw at any time, and given simple methods to do so
  • 21. 3) Demonstrate compliance New policies – data protection by design Regular audits Staff training Pseudonymisation Review and update existing information notices
  • 22. 4) Consider a data protection officer Informs and advises on obligations Monitors compliance – manages internal activities and audits, trains staff First point of contact for supervisory authorities and data subjects Compulsory that DPO:  Reports to board/directors  Independent, and not penalised for performing job  Has resources to meet obligations Can be existing employee as long as compatible and no conflict of interest No qualifications, but should have professional experience and knowledge of law
  • 24. DOWNLOAD GDPR TOOLKIT Q U A L I T Y . E Q M S . C O . U K / G D P R - G E N E R A L - D A T A - P R O T E C T I O N - R E G U L A T I O N - E U - T O O L K I T

Notes de l'éditeur

  1. General Data Protection Regulation Today's presentation is about the General Data Protection Regulation (GDPR), a new data protection law. First of all, bit of background information on the regulation – why it's being enforced and so on. Then go into a little more detail about what it means for businesses – how businesses will be affected, what they'll need to do to make sure they comply. Finish off by focusing on what it means for Qualsys in particular.
  2. General Data Protection Regulation
  3. General Data Protection Regulation
  4. General Data Protection Regulation It's the General Data Protection Regulation, and it's being enforced by the EU. Broadly similar to the UK Data Protection Act, deals with things such as fairness, lawfulness, transparency, data security, and confidentiality. Data protection laws in force in most EU countries for about 20 years, so many organisations already have basics in place and won’t need to make too many adjustments. It’s the first global data protection law in that any company worldwide that works with information relating to EU citizens MUST COMPLY. Not just limited to companies based in the EU. Centred around the use of “personal data”, which has always been a fairly broad definition but has changed a little in regards to GDPR. Comes into effect on 25 May 2018, regardless of Brexit.
  5. General Data Protection Regulation It's the General Data Protection Regulation, and it's being enforced by the EU. Broadly similar to the UK Data Protection Act, deals with things such as fairness, lawfulness, transparency, data security, and confidentiality. Data protection laws in force in most EU countries for about 20 years, so many organisations already have basics in place and won’t need to make too many adjustments. It’s the first global data protection law in that any company worldwide that works with information relating to EU citizens MUST COMPLY. Not just limited to companies based in the EU. Centred around the use of “personal data”, which has always been a fairly broad definition but has changed a little in regards to GDPR. Comes into effect on 25 May 2018, regardless of Brexit.
  6. General Data Protection Regulation
  7. General Data Protection Regulation Businesses will already be complying with the Data Protection Act and the existing EU Directive. But what new requirements does GDPR enforce? Expands definition of "personal data" – brings in some new categories of data that have mostly arisen due to the proliferation of the internet Transparency and consent – new requirements around obtaining permission from individuals to use their personal data, and justifying why you're using it Enhanced rights – GDPR gives data subjects several new rights, which we'll look at Accountability – holding organisations accountable is a big part of the new regulation. Organisations expected to adopt significant new measures to demonstrate that they're complying with GDPR.
  8. Expands definition set out in the DPA and the previous EU directive. "Personal data" still means things like names, ID numbers and physical information, but now also covers location data and online identifiers such as IP addresses and cookies. Data protection laws use the term "sensitive personal data" to cover things like race/ethnicity, politics, religious beliefs, sexual orientation etc. GDPR does the same, but also includes biometric and genetic data. Biometric data = any data relating to a person's physical, physiological or behavioural characteristics which allows them to be identified. Genetic data = any data relating to characteristics someone has inherited and which allows information about their health to be identified. As most organisations keep only HR records, customer lists, contact details etc., the change should make little practical difference. Can assume that if you hold information that falls within the scope of the DPA, also falls within the scope of the GDPR.
  9. General Data Protection Regulation Organisations have a duty to tell individuals how their personal data is processed. And they must do so in a format which is clear, concise and easily accessible. That information must include the legal basis for processing. For data processing to be legal under the GDPR, organisations must document why they're processing the data because this legal basis determines the individual's rights. If you're processing someone's data because they've explicitly given you their consent, for example, that person will generally have stronger rights. Other legal bases for processing data might be: Necessary to obey the law Necessary to perform a task in the public interest The information should also include details of any legitimate interests the organisation has for using the data. That could be direct marketing, preventing fraud, or making sure the IT networks are secure. The data subject should be told what right they have to lodge a complaint about how their data is stored and used, and how long their data will be retained.
  10. General Data Protection Regulation GDPR refers to both ‘consent’ and ‘explicit consent’, but is unclear as to the difference given that both forms have to be freely given, specific, informed and an unambiguous indication of the individual’s wishes. Consent under the GDPR requires some form of clear affirmative action, whether that's clicking a tick box or actively choosing a setting. Just because the person hasn't specifically said no doesn't mean they've said yes. And pre-ticked boxes are now banned. Consent to processing must be distinguishable, clear, and not “bundled” in with other written agreements. Consent must be verifiable. So some form of record must be kept of how and when the person gave their consent. Individuals have a right to withdraw consent at any time, and doing this should be as easy as it was for them to give their consent.
  11. General Data Protection Regulation At present, the average time between data breach and discover is 188 days. Under the new GDPR rules, this is not going to be acceptable. More robust systems are required to protect your organisation, customer and suppliers.
  12. General Data Protection Regulation Under GDPR, all organisations have a duty to report certain types of data breach to the relevant authority, and in some cases to the individuals affected. A personal data breach means a breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. For example, a hospital could be responsible for a personal data breach if a patient’s health record is inappropriately accessed due to a lack of appropriate internal controls. So a breach is more than just losing personal data. An organisation only has to notify the relevant supervisory authority of a breach where it is likely to put people's rights and freedoms at risk – so that might be causing discrimination, reputational damage, financial loss, or a loss of confidentiality. Where a breach is likely to put people's rights and freedoms at high risk, the organisation must notify those concerned directly. So the threshold for notifying individuals is higher than for notifying the relevant supervisory authority. A breach of this kind must be reported to the relevant supervisory authority within 72 hours of the organisation becoming aware of it. If the breach is serious enough to warrant notifying the public, the organisation must do so straight away. Failing to give notice of a breach could lead to a fine of up to 10 million Euros or two per cent of the business's global turnover.
  13. General Data Protection Regulation Accountability has always been an important element of data protection law, but the GDPR gives it more significance. "Data protection by design" means promoting privacy and data protection compliance from the start when beginning a new project (might be building a new IT system, or an initiative to share data with other organisations). Under the Data Protection Act, it was always a recommendation rather than an obligation. Under GDPR, organisations must be able to demonstrate their compliance with the principles of the regulation. How to do this? Could: Build into policies and procedures – e.g. new HR policies, carrying out regular audits Implement staff training programmes Use pseudonymisation – which is processing personal data in such a way that it can no longer be attributed to a specific "data subject" without the use of additional information, which must be kept separately and subject to the same measures If processing "high risk" data, now a formal requirement to carry out a data protection impact assessment to identify risks of non-compliance. Assessment must include a description of how and why data is processed, the risks involved, and measures employed to mitigate those risks. Any organisation can appoint a data protection officer (DPO) but public authorities, and organisations who process sensitive data or criminal records on a large scale or regularly monitor data subjects (e.g. tracking online behaviour), MUST do so.
  14. General Data Protection Regulation The GDPR gives data subjects a number of new rights when it comes to their personal data. They're entitled to: confirmation that their data is being processed, and to see a copy of that data have their personal data rectified if it's inaccurate or incomplete 'be forgotten' – so they can ask for their data to be deleted or removed if there's no longer a compelling reason for it to be processed restrict their personal data from being processed – for example, they might contest its accuracy, or need it for a legal claim. If processing is restricted, the organisation can store the data, just not process it obtain and reuse their personal data as they see fit.
  15. General Data Protection Regulation Accountability has always been an important element of data protection law, but the GDPR gives it more significance. "Data protection by design" means promoting privacy and data protection compliance from the start when beginning a new project (might be building a new IT system, or an initiative to share data with other organisations). Under the Data Protection Act, it was always a recommendation rather than an obligation. Under GDPR, organisations must be able to demonstrate their compliance with the principles of the regulation. How to do this? Could: Build into policies and procedures – e.g. new HR policies, carrying out regular audits Implement staff training programmes Use pseudonymisation – which is processing personal data in such a way that it can no longer be attributed to a specific "data subject" without the use of additional information, which must be kept separately and subject to the same measures If processing "high risk" data, now a formal requirement to carry out a data protection impact assessment to identify risks of non-compliance. Assessment must include a description of how and why data is processed, the risks involved, and measures employed to mitigate those risks. Any organisation can appoint a data protection officer (DPO) but public authorities, and organisations who process sensitive data or criminal records on a large scale or regularly monitor data subjects (e.g. tracking online behaviour), MUST do so.
  16. General Data Protection Regulation
  17. General Data Protection Regulation
  18. General Data Protection Regulation
  19. General Data Protection Regulation Our data protection policies must ensure that we tell people, during our first contact with them, that they have a right to object to our processing their data. All our staff will need to understand what constitutes a data breach, and that this is more than just a loss of data. We'll need to have internal procedures in place for detecting, investigating and reporting breaches. This will help us to decide who we need to notify. If there is a data breach and someone without the correct authority gets access to it, then the IT teams need to be able to implement appropriate measures to render the data unintelligible. We might also need to review our insurance policies to assess the extent of our coverage in case of any data breaches.
  20. General Data Protection Regulation In Qualsys's case, our legal basis for processing is likely to be that we're doing so with the subject's consent. If other reasons apply, we'll need to have processes that allow us to demonstrate how we've reached decisions on how we use data. If we're using consent as our basis for lawful processing, we need to make sure it's consent we've obtained correctly, in line with the provisions mentioned earlier. So clear affirmative action, consent given separately, and so on. We also need to ensure we make data subjects’ aware of the right to withdraw their consent at any time, and provide them with simple methods to do so.
  21. General Data Protection Regulation To demonstrate our compliance with GDPR, we’ll need to draw up a data protection policy. And if we do that from a data-protection-by-design standpoint, we can make sure we’re promoting privacy and data protection compliance from the very beginning. We can also strengthen our compliance by building certain measures into the policy, so, for example, conducting regular audits, training staff in data protection principles, pseudonymisation and so on.
  22. General Data Protection Regulation If we decide to appoint a DPO, there are a number of things we need to do to make sure they can operate to the best of their ability. As part of their role, the DPO would be: informing and advising the company about our obligations to comply with GDPR and other data protection laws; monitoring our compliance – including: managing internal data protection activities advising on data protection impact assessments training staff, and conducting internal audits; and the first point of contact for supervisory authorities and for individuals whose data is processed (employees, customers etc.). It’s compulsory that the DPO: reports to the board/directors operates independently and is not penalised for doing their job has sufficient resources to meet their GDPR obligations The DPO can be recruited from our existing pool of employees, but their duties would need to be compatible and avoid any conflict of interest. Whoever was chosen would not need any special qualifications, but should have professional experience and knowledge of data protection law.
  23. General Data Protection Regulation So, to finish, we know that in a year’s time there will be a new EU regulation that determines how businesses such as ours handle people’s personal data. We know that: the regulation gives people much stronger rights over their data we’ll have to be more transparent about how we use people’s data, and we’ll have a duty to demonstrate how we’re complying with the regulation overall. To do that, we’ll need to: review our policies and procedures establish our legal basis for using people’s data, and think about whether we need to appoint a data protection officer to do all the work for us.
  24. General Data Protection Regulation