SlideShare une entreprise Scribd logo
1  sur  10
European Union General Data
Protection Regulation(EU GDPR)
(May 2018 Implementation Date)
RAKESH CHANDRA
BUSINESS ANALYST
EU GDPR(General Data Protection
Regulation)
(Regulation (EU) 2016/679)
• The three Authority in Europe like European Parliament,
the European Council and the European Commission have
unified the data protection law for all individuals within
the European Union (EU) by passing the new GDPR(General
Data Protection Regulatory) Regulation & it will replace the
Current Data Protection Directive (officially Directive
95/46/EC),1995 Regulation.
• The main objectives of the GDPR are to give citizens and EU
residents back control of their personal data and to simplify
the regulatory environment for international business by
unifying the regulation within the EU.
Impact of GDPR Change
• Territorial & Digital Application:
The GDPR applies to non-EU organizations if they
offer goods or services to EU residents; or monitor the
behavior of EU residents. So EU GDPR law will
subject to specially Online business.
• Authorization:
In order for the processing of personal data to be lawful,
the controller requires either the Authorization of the data
subject or another lawful basis.
• The Personal Information or data is any information relating to an
individual, which is relates to his or her private, professional or
public life. Some data element example are name, a home address,
a photo, an email address, bank details, posts on social networking
websites, medical information, or a computer’s IP address.
• On the Data Breach case GDPR can be fined up to 4% of annual
global turnover or €20 Million (whichever is greater).
• Rights of data subjects
There are Some existing rights & created new as well as for data
subjects in the GDPR. These rights may make it harder for
organizations to lawfully process personal data. Some rights
example are:
 Right to be forgotten
 Right of rectification
 Right to restrict processing
 Right of data portability
 Right to object to processing
 Right to object to processing(For direct marketing, Scientific,
historical or statistical purposes)
 Right to not be evaluated on the basis of automated
processing
• Data breach notification (72 Hours):
The GDPR requires businesses to report data breaches to
the relevant DPA within 72 hours of detection.
• Data Protection Officer ("DPO") Appointing:
Organizations that regularly and systematically monitor
data subjects, or process Sensitive Personal Data on a
large scale, must appoint a DPO. A Data Protection Officer
("DPO") is a person who is formally tasked with ensuring
that an organization is aware of, and complies with, its data
protection responsibilities.
• Cross-Border Data Transfers
Cross-Border Data Transfer within a corporate group may
take place on the basis of Binding Corporate Rules
("BCRs").If the BCRs meet the requirements set out in the
GDPR, they will be approved, and no further DPA approval
will be required for transfers of personal data made under
the BCRs
GDPR Implementation Strategy
Stage 1
• Maturity Assessment
• Gap Analysis
Stage 2
• Transformation Strategy
• Impact Assessment
Stage 3
• Assurance & Stress Testing
• Personal Data Manage & Privacy Services
Implementation Process
• Gap analysis: Identifies gaps, proposes solutions and defines high-
level roadmap to compliance.
• PII(Personal Identifiable Information) Identification and Data
Mapping: Identifies the location and flow of Personal data in
business and IT Application and highlights areas for improvement.
• Incident management(IM) process: Review the processes for
identification and confirmation of a Data breach to meet the
notification timescale as per GDPR.
• 3rd Party assessments: Create and implement Solution to evaluate
security controls of third parties processing Personal Identifiable
data.
• Impact Assessment: Define and Implement the Impact Assessment
for Data Protection.
• Consulting & Data Protection Design : Consulting guidance for
technical solutions to meet GDPR requirements when implementing
Analytics data protection based on Data Protection Steps
***********************

Contenu connexe

Tendances

EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
VYTIS MALECKAS
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 

Tendances (20)

Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 

Similaire à EU GDPR(general data protection regulation)

GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
Jim Wilson
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
GrittyCC
 

Similaire à EU GDPR(general data protection regulation) (20)

De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de Poorter
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
GDPR master class accountable research organisations (january 2018)
GDPR master class   accountable research organisations (january 2018)GDPR master class   accountable research organisations (january 2018)
GDPR master class accountable research organisations (january 2018)
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
GDPR Quick Reference for American Accountants (CPA Seminar)
GDPR Quick Reference for American Accountants (CPA Seminar)GDPR Quick Reference for American Accountants (CPA Seminar)
GDPR Quick Reference for American Accountants (CPA Seminar)
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?Scott Appleton: GDPR - Big Bang or Data Evolution?
Scott Appleton: GDPR - Big Bang or Data Evolution?
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 

Dernier

Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
raffaeleoman
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
Kayode Fayemi
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
amilabibi1
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
Kayode Fayemi
 

Dernier (18)

Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptx
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
 
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
 
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
 
Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar Training
 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
 
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verifiedSector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
 
Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 
Dreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video TreatmentDreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video Treatment
 
Digital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of DrupalDigital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of Drupal
 

EU GDPR(general data protection regulation)

  • 1. European Union General Data Protection Regulation(EU GDPR) (May 2018 Implementation Date) RAKESH CHANDRA BUSINESS ANALYST
  • 2. EU GDPR(General Data Protection Regulation) (Regulation (EU) 2016/679) • The three Authority in Europe like European Parliament, the European Council and the European Commission have unified the data protection law for all individuals within the European Union (EU) by passing the new GDPR(General Data Protection Regulatory) Regulation & it will replace the Current Data Protection Directive (officially Directive 95/46/EC),1995 Regulation. • The main objectives of the GDPR are to give citizens and EU residents back control of their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.
  • 3. Impact of GDPR Change • Territorial & Digital Application: The GDPR applies to non-EU organizations if they offer goods or services to EU residents; or monitor the behavior of EU residents. So EU GDPR law will subject to specially Online business. • Authorization: In order for the processing of personal data to be lawful, the controller requires either the Authorization of the data subject or another lawful basis.
  • 4. • The Personal Information or data is any information relating to an individual, which is relates to his or her private, professional or public life. Some data element example are name, a home address, a photo, an email address, bank details, posts on social networking websites, medical information, or a computer’s IP address. • On the Data Breach case GDPR can be fined up to 4% of annual global turnover or €20 Million (whichever is greater).
  • 5. • Rights of data subjects There are Some existing rights & created new as well as for data subjects in the GDPR. These rights may make it harder for organizations to lawfully process personal data. Some rights example are:  Right to be forgotten  Right of rectification  Right to restrict processing  Right of data portability  Right to object to processing  Right to object to processing(For direct marketing, Scientific, historical or statistical purposes)  Right to not be evaluated on the basis of automated processing
  • 6. • Data breach notification (72 Hours): The GDPR requires businesses to report data breaches to the relevant DPA within 72 hours of detection. • Data Protection Officer ("DPO") Appointing: Organizations that regularly and systematically monitor data subjects, or process Sensitive Personal Data on a large scale, must appoint a DPO. A Data Protection Officer ("DPO") is a person who is formally tasked with ensuring that an organization is aware of, and complies with, its data protection responsibilities.
  • 7. • Cross-Border Data Transfers Cross-Border Data Transfer within a corporate group may take place on the basis of Binding Corporate Rules ("BCRs").If the BCRs meet the requirements set out in the GDPR, they will be approved, and no further DPA approval will be required for transfers of personal data made under the BCRs
  • 8. GDPR Implementation Strategy Stage 1 • Maturity Assessment • Gap Analysis Stage 2 • Transformation Strategy • Impact Assessment Stage 3 • Assurance & Stress Testing • Personal Data Manage & Privacy Services
  • 9. Implementation Process • Gap analysis: Identifies gaps, proposes solutions and defines high- level roadmap to compliance. • PII(Personal Identifiable Information) Identification and Data Mapping: Identifies the location and flow of Personal data in business and IT Application and highlights areas for improvement. • Incident management(IM) process: Review the processes for identification and confirmation of a Data breach to meet the notification timescale as per GDPR. • 3rd Party assessments: Create and implement Solution to evaluate security controls of third parties processing Personal Identifiable data. • Impact Assessment: Define and Implement the Impact Assessment for Data Protection.
  • 10. • Consulting & Data Protection Design : Consulting guidance for technical solutions to meet GDPR requirements when implementing Analytics data protection based on Data Protection Steps ***********************