SlideShare a Scribd company logo
@LibertyAppsUK@CYBERTALKLDN
GDPR
Understanding the
risks
@LibertyAppsUK@CYBERTALKLDN
Steve Hilton
@LibertyAppsUK@CYBERTALKLDN
Trusted Reviews
Apps That Mobilise Lives
4
Public Health England Hackathon winners
@LibertyAppsUK@CYBERTALKLDN
Liberty Apps
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
THE
IMPORTANT
STATS
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
GDPR compliance timeline
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Phase 1: Need to understand
@LibertyAppsUK@CYBERTALKLDN
Phase 2: Assess Risk
@LibertyAppsUK@CYBERTALKLDN
Phase 2: Assess Risk (1 of 2)
@LibertyAppsUK@CYBERTALKLDN
Phase 2: Assess Risk (2 of 2)
@LibertyAppsUK@CYBERTALKLDN
Phase 3: Implement
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Do we have a data retention policy?
It is down to the board of directors to decide what that retention
policy is, when and how will this approval be received? – data
must not be kept for any longer than is deemed necessary.
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
• How would we erase an individuals’ data?
• What is our process for correcting individuals’ data?
• Can we manage / remove consent for direct marketing and
automated decision making?
@LibertyAppsUK@CYBERTALKLDN
What will we do if a customer exercises their rights?
How would we handle a request?
What processes & policies do we have in place should we plan to refus
What will our partners whom we share data with need to do?
Do we have confidence that these partners are compliant and would no
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Employers can’t rely on employee consent to process HR
data
@LibertyAppsUK@CYBERTALKLDN
Employers can’t rely on employee consent to process HR
data
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
 What will we do if there is a breach?
 How would we detect, report and investigate a breach?
 To manage effective & efficient investigation:
Assess which types of data are held.
Document which types fall within the notification requirement
and the process to be followed if there is a breach.
@LibertyAppsUK@CYBERTALKLDN
Data Breach Notification
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/personal-data-breaches/
@LibertyAppsUK@CYBERTALKLDN
Optimal data breach notification timeline
@LibertyAppsUK@CYBERTALKLDN
Incident occurs
@LibertyAppsUK@CYBERTALKLDN
Clock starts
@LibertyAppsUK@CYBERTALKLDN
Key decisions
@LibertyAppsUK@CYBERTALKLDN
Notifications
@LibertyAppsUK@CYBERTALKLDN
Post notification period
@LibertyAppsUK@CYBERTALKLDN
Data Breach Notification
@LibertyAppsUK@CYBERTALKLDN
How would we implement an assessment in our organisation?
Who would carry it out?
Would it be run centrally or locally?
@LibertyAppsUK@CYBERTALKLDN
A data protection impact assessment (DPIA) is a process to help
you identify and minimise the data protection risks of a project.
Data protection impact assessments (DPIA)
@LibertyAppsUK@CYBERTALKLDN
Data protection impact assessments (DPIA)
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Phase 4: Demonstrate
@LibertyAppsUK@CYBERTALKLDN
Control over processes that collect and use personal
data?
@LibertyAppsUK@CYBERTALKLDN
Appropriate measures?
@LibertyAppsUK@CYBERTALKLDN
Ability to respond?
@LibertyAppsUK@CYBERTALKLDN
Records of what we do?
@LibertyAppsUK@CYBERTALKLDN
A published Privacy Notice
@LibertyAppsUK@CYBERTALKLDN
Consent and individual rights management.
@LibertyAppsUK@CYBERTALKLDN
@LibertyAppsUK@CYBERTALKLDN
Difficulty identifying and reporting a breach within 72
hours
2017 VERITAS GDPR REPORT
https://www.veritas.com/content/dam/Veritas/docs/reports/gdpr-report-ch2-en.pdf
@LibertyAppsUK@CYBERTALKLDN
Are former employees able to access company data?
2017 VERITAS GDPR REPORT
https://www.veritas.com/content/dam/Veritas/docs/reports/gdpr-report-ch2-en.pdf
@LibertyAppsUK@CYBERTALKLDN
The enemy within?
2017 Varonis Data Risk Report
https://info.varonis.com/hubfs/docs/research_reports/2017-data-risk-report.pdf
@LibertyAppsUK@CYBERTALKLDN
GDPR is an Evolutionary Process
@LibertyAppsUK@CYBERTALKLDN
Key Takeaway
@LibertyAppsUK@CYBERTALKLDN
Questions?Questions?
Steve@LibertyApps.co.
uk
@SteveHiltonCEO
+44 0161 883 2450
LibertyApps.co.uk

More Related Content

PDF
Experiencing the Mobile Mainframe
PDF
A Farmers Market of Open Data
KEY
News Applications: WAN-IFRA Presentation, Oct. 2011
PDF
Seguridad inform tica
PDF
2016 IQPC DDX Keynote - Paul Ricketts - Oracle
PDF
SnW18: opening slide
PDF
Aplicaciones web 2_0_google_docs
PDF
Aplicaciones web 2_0_google_docs
Experiencing the Mobile Mainframe
A Farmers Market of Open Data
News Applications: WAN-IFRA Presentation, Oct. 2011
Seguridad inform tica
2016 IQPC DDX Keynote - Paul Ricketts - Oracle
SnW18: opening slide
Aplicaciones web 2_0_google_docs
Aplicaciones web 2_0_google_docs

Similar to GDPR and Data Breach notifications (20)

PDF
GITA April 2015 Newsletter
PDF
Everyday Cryptography Fundamental Principles And Applications 2nd Edition Kei...
PDF
Data Protection Scotland Summit 2019
PDF
Technology_Industry_Survey_2015
PDF
Tech 15
PDF
The #BigData Dilemna
PPT
dppc-breach-notification-slides-201804.ppt
PDF
Role of CAs in cyber world
PDF
25 of the Best Tips from Twitter on Ethics, eDiscovery, and GTD
PPTX
Smart Data Module 5 d drive_legislation
PPTX
Virtual Gov Day - Introduction & Keynote - Alan Webber, IDC Government Insights
PDF
A Pratical Guide to GDPR - F.Coin
PDF
Data and Ethics: Why Data Science Needs One
PDF
Weekly eDiscovery Top Story Digest - March 5, 2014
PDF
2015 Conference Brochure - Trust Security Agility - Businesses Better Prepare...
PPTX
Capturing Opportunity involving Big Data & IoT at the age of IR 4.0 in Bangla...
PDF
Spotlight on Technology 2017
PDF
Privacy in the digital era
PPTX
IoT: How Data Science Driven Software is Eating the Connected World
PDF
Big data 4 4 the art of the possible 4-en-web
GITA April 2015 Newsletter
Everyday Cryptography Fundamental Principles And Applications 2nd Edition Kei...
Data Protection Scotland Summit 2019
Technology_Industry_Survey_2015
Tech 15
The #BigData Dilemna
dppc-breach-notification-slides-201804.ppt
Role of CAs in cyber world
25 of the Best Tips from Twitter on Ethics, eDiscovery, and GTD
Smart Data Module 5 d drive_legislation
Virtual Gov Day - Introduction & Keynote - Alan Webber, IDC Government Insights
A Pratical Guide to GDPR - F.Coin
Data and Ethics: Why Data Science Needs One
Weekly eDiscovery Top Story Digest - March 5, 2014
2015 Conference Brochure - Trust Security Agility - Businesses Better Prepare...
Capturing Opportunity involving Big Data & IoT at the age of IR 4.0 in Bangla...
Spotlight on Technology 2017
Privacy in the digital era
IoT: How Data Science Driven Software is Eating the Connected World
Big data 4 4 the art of the possible 4-en-web
Ad

More from Steve Hilton (16)

PDF
How Smart Are Cities
PDF
Meetups
PDF
Manchester College
PDF
Amazon Go
PDF
AI and Jobs
PDF
Liberty Apps Culture Deck
PDF
Appocalypse, or How I Learned to Stop Worrying and Love AI
PDF
What Touring 3 Tech Giants Taught Liberty Apps About Culture
PPTX
Netflix
PPTX
Google
PPTX
Linkedin
PPTX
The Revolution Will Not Be Televised… It’s screenless
PDF
Manchester Tech Community 2.0
PDF
Digital Transformation
PPTX
User Experience for Android
PPTX
Maximising UX for Mobile Applications
How Smart Are Cities
Meetups
Manchester College
Amazon Go
AI and Jobs
Liberty Apps Culture Deck
Appocalypse, or How I Learned to Stop Worrying and Love AI
What Touring 3 Tech Giants Taught Liberty Apps About Culture
Netflix
Google
Linkedin
The Revolution Will Not Be Televised… It’s screenless
Manchester Tech Community 2.0
Digital Transformation
User Experience for Android
Maximising UX for Mobile Applications
Ad

Recently uploaded (20)

PDF
Notes to accompany the TMT and FRAND Overview Slides
PPTX
What Happens to Your Business If You Become Incapacitated
PPTX
BUSINESS LAW AND IT IN CONTRACT SIGNING AND MANAGEMENT
PDF
NRL_Legal Regulation of Forests and Wildlife.pdf
PPT
Cyber-Crime-in- India at Present day and Laws
PPTX
ART OF LEGAL WRITING IN THE CBD [Autosaved].pptx
PPTX
PART-3-FILIPINO-ADMINISTRATIVE-CULTURE.pptx
PPT
Understanding the Impact of the Cyber Act
PPTX
Sexual Harassment Prevention training class
PPTX
UDHR & OTHER INTERNATIONAL CONVENTIONS.pptx
PPTX
Basic key concepts of law by Shivam Dhawal
PPTX
BL 2 - Courts and Alternative Dispute Resolution.pptx
PDF
Vinayaka Mission Law School Courses and Infrastructure.pdf
PPTX
PoSH act in a nutshell by Lovely Kumari .pptx
PPTX
2.....FORMULATION OF THE RESEARCH PROBLEM.pptx
PDF
250811-FINAL-Bihar_Voter_Deletion_Analysis_Presentation.pdf
PPTX
Income under income Tax Act..pptx Introduction
PDF
OpenAi v. Open AI Summary Judgment Order
PPTX
Law of Torts , unit I for BA.LLB integrated course
PPTX
Behavioural_Approach_Public_Administration_Zambia_USA.pptx
Notes to accompany the TMT and FRAND Overview Slides
What Happens to Your Business If You Become Incapacitated
BUSINESS LAW AND IT IN CONTRACT SIGNING AND MANAGEMENT
NRL_Legal Regulation of Forests and Wildlife.pdf
Cyber-Crime-in- India at Present day and Laws
ART OF LEGAL WRITING IN THE CBD [Autosaved].pptx
PART-3-FILIPINO-ADMINISTRATIVE-CULTURE.pptx
Understanding the Impact of the Cyber Act
Sexual Harassment Prevention training class
UDHR & OTHER INTERNATIONAL CONVENTIONS.pptx
Basic key concepts of law by Shivam Dhawal
BL 2 - Courts and Alternative Dispute Resolution.pptx
Vinayaka Mission Law School Courses and Infrastructure.pdf
PoSH act in a nutshell by Lovely Kumari .pptx
2.....FORMULATION OF THE RESEARCH PROBLEM.pptx
250811-FINAL-Bihar_Voter_Deletion_Analysis_Presentation.pdf
Income under income Tax Act..pptx Introduction
OpenAi v. Open AI Summary Judgment Order
Law of Torts , unit I for BA.LLB integrated course
Behavioural_Approach_Public_Administration_Zambia_USA.pptx

GDPR and Data Breach notifications