SlideShare a Scribd company logo
GDPR
Note: This presentation is not a legal
advice for your company to use in
complying with EU data privacy laws
like the GDPR.
GDPR stands for
General Data Protection
Regulation.
Around May 25, 2018
Key Terms
1. Data
2. Data subject
3. Data Controllers
4. Data Processors
Understanding GDPR
and the Key Changes
Fines can add up to 4% of annual global
turnover or 20 Million Euros
€’000 → €’000,000
Previously fines were limited based on the size and the scope
of the impact.
GDPR fines will apply to both controllers and processors.
Key Changes of the GDPR
GDPR will cover more Territory
EU → World
GDPR will apply to all companies processing the
personal data of data subjects residing in the EU,
regardless of the company’s location.
Key Changes of the GDPR
Explicit and retractable consent
Must be provided in an intelligible and easily
accessible form, using clear and plain
language. It must be as easy to withdraw
consent as it is to give it.
Key Changes of the GDPR
Right to access and portability
Data subjects can request confirmation as to whether
or not personal data concerning them is being
processed, where and for what purpose. Further, the
controller shall provide a copy of the personal data,
free of charge, in an electronic format.
Key Changes of the GDPR
Breach notification within 72 hours
Now mandatory that breaches, which are likely to
“result in a risk for the rights and freedoms of
individuals”, are reported within 72 hours of first having
become aware of the breach.
Key Changes of the GDPR
72
Design privacy embedded systems
Now a legal requirement for the inclusion of data
protection from the onset of the designing of systems,
rather than a retrospective addition.
Key Changes of the GDPR
Right to be forgotten
Entitles the data subject to have the data controller
erase his/ her personal data, cease further
dissemination of the data, and potentially have third
parties halt processing of the data.
Key Changes of the GDPR
Your name
Last name
Age
Mandatory Data Protection Officers
A Data protection officer is mandatory for certain types of organizations.
Key Changes of the GDPR
All the different areas of your Organization
that will be affected by GDPR
● Legal and Compliance,
● Technology and
● Data
Legal & Compliance
● Many organizations will require to appoint a Data Protection Officer (DPO).
(refer article 37-39)
● There are estimates that there will be 28,000 new DPO’s in Europe alone.
● More emphasis is given on how organizations review their privacy policy
so that it is easier for visitors to understand
How the Legal & Compliance areas are affected
● With a fine as high as 4% of the overall income - there is a lot more
enforcement that will take place
● There will be more accountability requirements for organizations to prove
that they are GDPR compliant with regulators
● An increased demand for data officers will make it a challenge to find
qualified and competent professionals due to their short supply
● Organizations will have to provide more clarity and education
transparently to customers
From the Technology perspective
● When a security breach occurs, organizations will have 72 hours to report
it to regulators
● Individuals have the option to “opt-out” of being tracked and from having
their information being shared with third-party organizations and websites
● Even if organizations have encryption, they will still have to focus heavily
on how their data infrastructure is set up. This ultimately means that they
can’t be careless regardless of having encryption on their end
● There is more emphasis on “Privacy by Design” based on how new
technologies are deployed.
Data Storage Best Practices
● Organizations will have to demonstrate how they store their data, what
information is stored and how it is shared
● Data portability allows customers to request a copy of their data based on
a standardized format
● Customers have the right to be forgotten and can have their information
and data on them to be deleted
● There is more emphasis on the classification of data based on the
information being pseudo-anonymous
How to make sure that Your Organization is
compliant with GDPR
● Notify the key people in your organization about GDPR and the
compliance rules and regulations around it
● Assess your organization based on the above key points to verify what
needs to be done in order to make it GDPR compliant
● Put together the inventory of all the data collected, stored and with whom
that data is shared as well as how it is governed
● Implement GDPR by taking the approach on how data privacy is governed
and what are the associated roles and responsibilities
How to make sure that Your Organization is
compliant with GDPR (continued)
● Determine how compliance will be demonstrated, how your organization
will capture the consent of customers and how to make your privacy
policy more transparent in order to educate and inform customers
● Implement and deploy technology in order to comply with Privacy by
Design
● Make sure that your Organization has the right data governance policies
in place in order to respond effectively to the individual’s rights based on
GDPR
● Updating contracts with 3rd party tools that process customer data
● Cookie notification popup
● Keep a record of all European opt-ins
● Updating privacy policy and terms of services
F.A.Q
Do we need Double opt-in?
Was I suppose to send a re-optin before May
25th?
People Celebrating After GDPR
Thank you
Some Resources
1. Suzanne Dibble’s Facebook group -
https://www.facebook.com/groups/GDPRforonlineentrepreneurs/
2. GDPR Website https://gdpr-info.eu/chapter-2/
3. For Organizations https://ico.org.uk/for-organisations/guide-to-the-
general-data-protection-regulation-gdpr/
4. DELOITTE and GDPR / http://bit.ly/2JZIyYq
5. Hubspot and GDPR / http://bit.ly/gdprhubspot
6. Privacy Policy with GDPR by Termsfeed / http://bit.ly/gdprandprivacy
Neha Patel
www.web247.solutions
Email: neha@web247.solutions

More Related Content

PPTX
An Overview of GDPR
PDF
Employee Training is Key to GDPR Compliance: GDPR
PPTX
What is GDPR?
PDF
General data protection regulation gdpr audit 2018
PPTX
GDPR
PPTX
EU GDPR(general data protection regulation)
PPTX
GDPR: Training Materials by Qualsys
An Overview of GDPR
Employee Training is Key to GDPR Compliance: GDPR
What is GDPR?
General data protection regulation gdpr audit 2018
GDPR
EU GDPR(general data protection regulation)
GDPR: Training Materials by Qualsys

What's hot (20)

PPTX
GDPR Compliance: What You Need to Know Before May 2018
PDF
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
PDF
Understanding gdpr compliance gdpr analytics tools
PDF
GDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
PPTX
Gdpr presentation
PDF
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
PPTX
The Practical Impact of the General Data Protection Regulation
PPTX
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
PDF
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
PDF
GDPR for Dummies
PPTX
Gdpr action plan - ISSA
PPTX
An Overview Of GDPR (General Data Protection Regulation)
PDF
Data breaches, privacy programs and what will change for processors
PPTX
Getting Ready for GDPR
PPTX
Impact of GDPR on Data Collection and Processing
PDF
GDPR Data Subject Rights - What You Need to Know
PDF
The Essential Guide to GDPR
PPTX
EU GDPR - 12 Steps To Compliance
PDF
GDPR-Overview
GDPR Compliance: What You Need to Know Before May 2018
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
Understanding gdpr compliance gdpr analytics tools
GDPR Compliance Software | General Data Protection Regulation (GDPR) Dashboard
Gdpr presentation
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
The Practical Impact of the General Data Protection Regulation
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
GDPR for Dummies
Gdpr action plan - ISSA
An Overview Of GDPR (General Data Protection Regulation)
Data breaches, privacy programs and what will change for processors
Getting Ready for GDPR
Impact of GDPR on Data Collection and Processing
GDPR Data Subject Rights - What You Need to Know
The Essential Guide to GDPR
EU GDPR - 12 Steps To Compliance
GDPR-Overview
Ad

Similar to A Brief Overview on GDPR (20)

PPTX
GDPR - what you need to know
PDF
What's Next - General Data Protection Regulation (GDPR) Changes
PPTX
General Data Protection Regulation (GDPR) Implications for Canadian Firms
PPTX
General Data Protection Regulation (GDPR) Compliance
PPTX
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
PDF
How the EU-GDPR May Affect Your Website
PPTX
Gdpr action plan
PPTX
Understanding the EU's new General Data Protection Regulation (GDPR)
PDF
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
PDF
LW-Privacy-GDPR-Compliance-Checklist.pdf
PDF
GDPRIBMWhitePaper
PPTX
Operational impact of gdpr finance industries in the caribbean
PDF
The Countdown to the GDPR Regulations
PDF
Are you GDPR Ready? Checklist Whitepaper
PPTX
General Data Protection Regulation
PDF
GDPR & Data Privacy Guide - Free Download
PPTX
GDPR SECURITY ISSUES
PDF
GDPR: What does it mean for your business?
PPTX
Taking the Fear Out of GDPR
PDF
ICO's Guide to Preparing for the GDPR
GDPR - what you need to know
What's Next - General Data Protection Regulation (GDPR) Changes
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Compliance
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
How the EU-GDPR May Affect Your Website
Gdpr action plan
Understanding the EU's new General Data Protection Regulation (GDPR)
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
LW-Privacy-GDPR-Compliance-Checklist.pdf
GDPRIBMWhitePaper
Operational impact of gdpr finance industries in the caribbean
The Countdown to the GDPR Regulations
Are you GDPR Ready? Checklist Whitepaper
General Data Protection Regulation
GDPR & Data Privacy Guide - Free Download
GDPR SECURITY ISSUES
GDPR: What does it mean for your business?
Taking the Fear Out of GDPR
ICO's Guide to Preparing for the GDPR
Ad

Recently uploaded (20)

PDF
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
PPTX
Probability Distribution, binomial distribution, poisson distribution
PDF
How to Get Funding for Your Trucking Business
PDF
Nidhal Samdaie CV - International Business Consultant
PDF
Tata consultancy services case study shri Sharda college, basrur
PDF
Outsourced Audit & Assurance in USA Why Globus Finanza is Your Trusted Choice
PDF
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
PPTX
2025 Product Deck V1.0.pptxCATALOGTCLCIA
PDF
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
PPT
Lecture 3344;;,,(,(((((((((((((((((((((((
PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PDF
Deliverable file - Regulatory guideline analysis.pdf
PDF
Daniels 2024 Inclusive, Sustainable Development
PDF
Chapter 5_Foreign Exchange Market in .pdf
PDF
How to Get Business Funding for Small Business Fast
PDF
Digital Marketing & E-commerce Certificate Glossary.pdf.................
PDF
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
PDF
Ôn tập tiếng anh trong kinh doanh nâng cao
PDF
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
PDF
Roadmap Map-digital Banking feature MB,IB,AB
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
Probability Distribution, binomial distribution, poisson distribution
How to Get Funding for Your Trucking Business
Nidhal Samdaie CV - International Business Consultant
Tata consultancy services case study shri Sharda college, basrur
Outsourced Audit & Assurance in USA Why Globus Finanza is Your Trusted Choice
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
2025 Product Deck V1.0.pptxCATALOGTCLCIA
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
Lecture 3344;;,,(,(((((((((((((((((((((((
Power and position in leadershipDOC-20250808-WA0011..pdf
Deliverable file - Regulatory guideline analysis.pdf
Daniels 2024 Inclusive, Sustainable Development
Chapter 5_Foreign Exchange Market in .pdf
How to Get Business Funding for Small Business Fast
Digital Marketing & E-commerce Certificate Glossary.pdf.................
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
Ôn tập tiếng anh trong kinh doanh nâng cao
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
Roadmap Map-digital Banking feature MB,IB,AB

A Brief Overview on GDPR

  • 2. Note: This presentation is not a legal advice for your company to use in complying with EU data privacy laws like the GDPR.
  • 3. GDPR stands for General Data Protection Regulation.
  • 5. Key Terms 1. Data 2. Data subject 3. Data Controllers 4. Data Processors
  • 7. Fines can add up to 4% of annual global turnover or 20 Million Euros €’000 → €’000,000 Previously fines were limited based on the size and the scope of the impact. GDPR fines will apply to both controllers and processors. Key Changes of the GDPR
  • 8. GDPR will cover more Territory EU → World GDPR will apply to all companies processing the personal data of data subjects residing in the EU, regardless of the company’s location. Key Changes of the GDPR
  • 9. Explicit and retractable consent Must be provided in an intelligible and easily accessible form, using clear and plain language. It must be as easy to withdraw consent as it is to give it. Key Changes of the GDPR
  • 10. Right to access and portability Data subjects can request confirmation as to whether or not personal data concerning them is being processed, where and for what purpose. Further, the controller shall provide a copy of the personal data, free of charge, in an electronic format. Key Changes of the GDPR
  • 11. Breach notification within 72 hours Now mandatory that breaches, which are likely to “result in a risk for the rights and freedoms of individuals”, are reported within 72 hours of first having become aware of the breach. Key Changes of the GDPR 72
  • 12. Design privacy embedded systems Now a legal requirement for the inclusion of data protection from the onset of the designing of systems, rather than a retrospective addition. Key Changes of the GDPR
  • 13. Right to be forgotten Entitles the data subject to have the data controller erase his/ her personal data, cease further dissemination of the data, and potentially have third parties halt processing of the data. Key Changes of the GDPR Your name Last name Age
  • 14. Mandatory Data Protection Officers A Data protection officer is mandatory for certain types of organizations. Key Changes of the GDPR
  • 15. All the different areas of your Organization that will be affected by GDPR ● Legal and Compliance, ● Technology and ● Data
  • 16. Legal & Compliance ● Many organizations will require to appoint a Data Protection Officer (DPO). (refer article 37-39) ● There are estimates that there will be 28,000 new DPO’s in Europe alone. ● More emphasis is given on how organizations review their privacy policy so that it is easier for visitors to understand
  • 17. How the Legal & Compliance areas are affected ● With a fine as high as 4% of the overall income - there is a lot more enforcement that will take place ● There will be more accountability requirements for organizations to prove that they are GDPR compliant with regulators ● An increased demand for data officers will make it a challenge to find qualified and competent professionals due to their short supply ● Organizations will have to provide more clarity and education transparently to customers
  • 18. From the Technology perspective ● When a security breach occurs, organizations will have 72 hours to report it to regulators ● Individuals have the option to “opt-out” of being tracked and from having their information being shared with third-party organizations and websites ● Even if organizations have encryption, they will still have to focus heavily on how their data infrastructure is set up. This ultimately means that they can’t be careless regardless of having encryption on their end ● There is more emphasis on “Privacy by Design” based on how new technologies are deployed.
  • 19. Data Storage Best Practices ● Organizations will have to demonstrate how they store their data, what information is stored and how it is shared ● Data portability allows customers to request a copy of their data based on a standardized format ● Customers have the right to be forgotten and can have their information and data on them to be deleted ● There is more emphasis on the classification of data based on the information being pseudo-anonymous
  • 20. How to make sure that Your Organization is compliant with GDPR ● Notify the key people in your organization about GDPR and the compliance rules and regulations around it ● Assess your organization based on the above key points to verify what needs to be done in order to make it GDPR compliant ● Put together the inventory of all the data collected, stored and with whom that data is shared as well as how it is governed ● Implement GDPR by taking the approach on how data privacy is governed and what are the associated roles and responsibilities
  • 21. How to make sure that Your Organization is compliant with GDPR (continued) ● Determine how compliance will be demonstrated, how your organization will capture the consent of customers and how to make your privacy policy more transparent in order to educate and inform customers ● Implement and deploy technology in order to comply with Privacy by Design ● Make sure that your Organization has the right data governance policies in place in order to respond effectively to the individual’s rights based on GDPR ● Updating contracts with 3rd party tools that process customer data ● Cookie notification popup ● Keep a record of all European opt-ins ● Updating privacy policy and terms of services
  • 22. F.A.Q
  • 23. Do we need Double opt-in?
  • 24. Was I suppose to send a re-optin before May 25th?
  • 27. Some Resources 1. Suzanne Dibble’s Facebook group - https://www.facebook.com/groups/GDPRforonlineentrepreneurs/ 2. GDPR Website https://gdpr-info.eu/chapter-2/ 3. For Organizations https://ico.org.uk/for-organisations/guide-to-the- general-data-protection-regulation-gdpr/ 4. DELOITTE and GDPR / http://bit.ly/2JZIyYq 5. Hubspot and GDPR / http://bit.ly/gdprhubspot 6. Privacy Policy with GDPR by Termsfeed / http://bit.ly/gdprandprivacy