SlideShare a Scribd company logo
2
Most read
3
Most read
6
Most read
Data Protection & Privacy
Source: European Union: ECJ Inv alidates Data Retention Directiv e by Theresa Papademetriou | EU General Data Protection Regulation
and what it means f or SaaS companies in 2017 and 2018 by Megan Lozicki, Niklas Skog, Diego Checa | GDPR – Timeline by Bird & Bird | A v isual timeline f or implementing the GDPR in the UK
EU Data Protection Reform
The EU 1995 Data Protection Directive was archaic and non-legally binding for
every member state; reform was necessary to improve data protection and privacy
1995: The Data Protection Directive
(DPP), officially Directive 95/46/EC is
passed.
The directive establishes that the
ownership of personal data belongs to
individuals, who have legal rights over the
collection and processing of personal data.
2000: The US-EU Safe Harbour Framework are created
as an addition to the 1995 DPP.
US companies that comply with the principles and
register their certification, such that they fulfill EU
requirements, are allowed to transfer data from the EU
to the US.
2011: Viviane Reding,
the VP of the European
Commission,
introduces the EU data
protection reform.
2012: The legislative
proposal of the new General
Data Protection Regulation
(GDPR) is published and
negotiations begin amongst
European parliaments.
2015: The Safe Harbour
framework is invalidated
by the CJEU as a result
of the Schrems vs Data
Protection Commissioner
case.
2016: The new GDPR is
approved on 14th April.
The EU-US Privacy Shield
framework is approved on
12th July, to replace the
Safe Harbour agreement.
2018: The GDPR
will officially replace
the 1995 DPP on
25th May.
General Data Protection Regulation
The new regulation is expected to increase privacy for individuals and provide
regulators with more power to take action against businesses in breach
Extended Jurisdiction
• Applies to all businesses processing personal data of
data subjects who are in the EU, regardless of
company location and where the processing is carried
out
Consent
• Requests for consent must be
intelligible and easily
accessible, using clear and
plain language
• An affirmative action signalling
consent is required
• Consent should be as easily
withdrawn as to give it
• Requires parental consent for
processing children’s personal
data
Right to Access
• Data subjects have the right to obtain confirmation
from the data controller as to whether their personal
data is being processed, where and for what purpose
Right to be Forgotten
• Data subjects have the right to demand the data
controller to erase their personal data, cease further
dissemination of the data, and potentially have third
parties halt processing of the data
Breach Notification
• Mandatory to notify authorities
within 72 hours of first having
become aware of a data breach
• Data processors must notify their
controllers
Source: EU GDPR | Top 10 operational impacts of the GDPR: Part 1 – data security and breach notif ication by Rita Heimes | MANAGE THE TOP 4 GDPR OPERATIONAL
IMPACTS (PART I) by Donna Recchione | MANAGE THE TOP 10 GDPR OPERATIONAL IMPACTS (PART II) by Donna Recchione
General Data Protection Regulation
Including hefty penalties for violations - fines of up to 4% of the company’s
worldwide annual turnover or EUR 20M, whichever is higher
Penalties for Violations
• Fine up to 4% of the company’s
worldwide annual turnover or EUR 20M,
whichever is higher
Cross-border Data Transfers
• Personal data transfers permitted
to a third country or international
organization will be subject to
compliance
• In the absence of an adequacy
decision, transfers are still
allowed under certain
circumstances, such as by use of
standard contractual clauses or
binding corporate rules
Data Protection Officers
• Large firms and companies that process specialized
data must assign a qualified DPO for GDPR
compliance
Data Portability
• Data subjects have the right to receive their personal
data in a commonly used and machine readable
format
• They have the right to transmit that data to another
controller
Restricted Profiling
• Data subjects have the right not to
be subject to a decision based
solely on automated processing,
which produces legal effects or
significantly affects them, without
human intervention
Source: EU GDPR | Top 10 operational impacts of the GDPR: Part 1 – data security and breach notif ication by Rita Heimes | MANAGE THE TOP 4 GDPR OPERATIONAL
IMPACTS (PART I) by Donna Recchione | MANAGE THE TOP 10 GDPR OPERATIONAL IMPACTS (PART II) by Donna Recchione | Top 10 operational impacts of the
GDPR: Part 4 - Cross-border data transf ers by Anna My ers
Source: 2018 Tech Vendor Report by iapp
Privacy Tech Industry
Driving the need for an array of solutions to decisively address a slew of privacy
compliance challenges
Activity Monitoring Consent Manager
Data Discovery
Data Mapping
Pseudonymity
Enterprise
Communications
Incident Response
Website Scanning
Assessment Manager
Privacy Tech Industry
Leading to robust vendor growth and increase in solutions offered; with products
targeting core compliance requirements accounting for >75% of the industry
Source: 2018 Tech Vendor Report by iapp | 2017 Tech Vendor Report by iapp
• Vendors are currently focusing on meeting core compliance
requirements (via activity monitoring, assessment managers, consent
managers, data discovery and data mapping)
• Solutions targeting these areas make up 77% of the industry
• They are integral to achieving primary regulatory compliance
• Other aspects of privacy compliance remain largely untapped,
presenting potential market opportunities for startups
• The privacy tech industry is booming as
evidenced by the robust vendor growth last
year
• Existing vendors have also built out new
privacy technology services in the last year,
adding to industry dynamics
43
51
67
98
122
0
20
40
60
80
100
120
140
Q1 2017 Q2 Q3 Q4 Q1 2018
Number of Vendors
Website
Scanning
4%
Incident
Response
8%Enterprise
Communications
4%
Pseudonymity
7%
Data Mapping
19%
Data Discovery
16%
Consent Manager
11%
Assessment
Manager
16%
Activity Monitoring
15%
Looking Ahead
• Reform of the archaic EU 1995 DPP was necessary to improve data protection and privacy
• The new regulation is expected to increase privacy for individuals, provide regulators with more power to take action
against businesses in breach
• Complexity in managing data is driving the need for solutions to address privacy compliance challenges
• Existing vendors are primarily focused on producing solutions revolving around assessment managers, activity
monitoring, data discovery, data mapping, consent managers
• Other aspects of privacy compliance remain largely untapped, presenting potential market opportunities for startups
• Whilst most solutions target resolving compliance issues within client datacenters, a small minority have identified the
need for data management in the cloud as well as in mobile applications
• Privacy technology tools certainly look interesting but companies need to be careful as these external solutions may
introduce new enterprise risks
About Vertex Ventures
Vertex Ventures is a global network of operator-investors who manage portfolios in the U.S., China,
Israel, India and Southeast Asia.
Vertex teams combine firsthand experience in transformational technologies; on-the-ground
knowledge in the world’s major innovation centers; and global context, connections and customers.
Yanai Oron
General Partner
Vertex Ventures Israel
yanai@vertexventures.com

More Related Content

PPTX
Privacy & Data Protection
PDF
Data Privacy & Security
PDF
Capital Expenditure PowerPoint Presentation Slides
PDF
GDPR Basics - General Data Protection Regulation
PDF
Overview on data privacy
PPTX
5 BENIFITES OF CHAT GPT.pptx
PDF
Computer Ethics: Some Case Study
PPTX
Data protection ppt
Privacy & Data Protection
Data Privacy & Security
Capital Expenditure PowerPoint Presentation Slides
GDPR Basics - General Data Protection Regulation
Overview on data privacy
5 BENIFITES OF CHAT GPT.pptx
Computer Ethics: Some Case Study
Data protection ppt

What's hot (20)

PDF
Data & Privacy: Striking the Right Balance - Jonny Leroy
PDF
Privacy and Data Security
PPTX
Data Privacy: What you need to know about privacy, from compliance to ethics
PPT
Data protection in_india
PPTX
Data Privacy Introduction
PPT
“Privacy Today” Slide Presentation
PPTX
Data Privacy and Protection Presentation
PPT
Data Protection Presentation
PPT
Data Privacy in India and data theft
PPTX
GDPR Introduction and overview
PPTX
Data protection
PPT
Physical Security
PPTX
Data Security - English
PDF
Information Security Awareness Training
PPTX
what is data security full ppt
PPTX
Security Awareness Training - For Companies With Access to NYS "Sensitive" In...
PPTX
Security Awareness Training.pptx
PDF
Privacy & Data Protection in the Digital World
PPTX
Social Media Cyber Security Awareness Briefing
PDF
Security Awareness Training
Data & Privacy: Striking the Right Balance - Jonny Leroy
Privacy and Data Security
Data Privacy: What you need to know about privacy, from compliance to ethics
Data protection in_india
Data Privacy Introduction
“Privacy Today” Slide Presentation
Data Privacy and Protection Presentation
Data Protection Presentation
Data Privacy in India and data theft
GDPR Introduction and overview
Data protection
Physical Security
Data Security - English
Information Security Awareness Training
what is data security full ppt
Security Awareness Training - For Companies With Access to NYS "Sensitive" In...
Security Awareness Training.pptx
Privacy & Data Protection in the Digital World
Social Media Cyber Security Awareness Briefing
Security Awareness Training
Ad

Similar to Data Protection and Privacy (20)

PPTX
General Data Protection Regulation (GDPR) Implications for Canadian Firms
PDF
What's Next - General Data Protection Regulation (GDPR) Changes
PPTX
EU GDPR(general data protection regulation)
PPTX
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
PDF
GDPR Overview
PDF
GDPR what you should know and how to minimize impact on your business
PPTX
De groote de man Ingrid de Poorter
PPTX
A Brief Overview on GDPR
PPTX
Gdpr action plan
PDF
GDPR for your Payroll Bureau
PDF
EY General Data Protection Regulation: Are you ready?
PPTX
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
PPTX
General Data Protection Regulation
PPTX
Domain management and brand protection in the era of the EU's GDPR
PPTX
GDPR in the Digital World
PPTX
The first steps towards GDPR compliance 
PDF
GDPRIBMWhitePaper
PPTX
GDPR in the Healthcare Industry
PDF
GDPR for your Payroll Bureau
PDF
GDPR: What does it mean for your business?
General Data Protection Regulation (GDPR) Implications for Canadian Firms
What's Next - General Data Protection Regulation (GDPR) Changes
EU GDPR(general data protection regulation)
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
GDPR Overview
GDPR what you should know and how to minimize impact on your business
De groote de man Ingrid de Poorter
A Brief Overview on GDPR
Gdpr action plan
GDPR for your Payroll Bureau
EY General Data Protection Regulation: Are you ready?
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
General Data Protection Regulation
Domain management and brand protection in the era of the EU's GDPR
GDPR in the Digital World
The first steps towards GDPR compliance 
GDPRIBMWhitePaper
GDPR in the Healthcare Industry
GDPR for your Payroll Bureau
GDPR: What does it mean for your business?
Ad

More from Vertex Holdings (20)

PDF
Third-Generation Semiconductor: The Next Wave?
PDF
E-mobility E-mobility | Part 5 - The future of EVs and AVs (English)
PDF
E-mobility | Part 5 - The future of EVs and AVs (Japanese)
PDF
E-mobility | Part 5 - The future of EVs and AVs (German)
PDF
E-mobility | Part 5 - The future of EVs and AVs (Chinese)
PDF
E-mobility | Part 5 - The future of EVs and AVs (Korean)
PDF
E-mobility | Part 3 - Battery recycling & power electronics (German)
PDF
E-mobility | Part 3 - Battery recycling & power electronics (Japanese)
PDF
E-mobility | Part 4 - EV charging and the next frontier (Korean)
PDF
E-mobility | Part 4 - EV charging and the next frontier (Japanese)
PDF
E-mobility | Part 4 - EV charging and the next frontier (Chinese)
PDF
E-mobility | Part 4 - EV charging and the next frontier (German)
PDF
E-mobility | Part 4 - EV charging and the next frontier (English)
PDF
E-mobility | Part 3 - Battery Technology & Alternative Innovations (Korean)
PDF
E-mobility | Part 3 - Battery Technology & Alternative Innovations (Chinese)
PDF
E-mobility | Part 3 - Battery recycling & power electronics (English)
PDF
E-mobility | Part 2 - Battery Technology & Alternative Innovations (German)
PDF
E-mobility | Part 2 - Battery Technology & Alternative Innovations (Chinese)
PDF
E-mobility | Part 2 - Battery Technology & Alternative Innovations (Japanese)
PDF
E-mobility | Part 2 - Battery Technology & Alternative Innovations (Korean)
Third-Generation Semiconductor: The Next Wave?
E-mobility E-mobility | Part 5 - The future of EVs and AVs (English)
E-mobility | Part 5 - The future of EVs and AVs (Japanese)
E-mobility | Part 5 - The future of EVs and AVs (German)
E-mobility | Part 5 - The future of EVs and AVs (Chinese)
E-mobility | Part 5 - The future of EVs and AVs (Korean)
E-mobility | Part 3 - Battery recycling & power electronics (German)
E-mobility | Part 3 - Battery recycling & power electronics (Japanese)
E-mobility | Part 4 - EV charging and the next frontier (Korean)
E-mobility | Part 4 - EV charging and the next frontier (Japanese)
E-mobility | Part 4 - EV charging and the next frontier (Chinese)
E-mobility | Part 4 - EV charging and the next frontier (German)
E-mobility | Part 4 - EV charging and the next frontier (English)
E-mobility | Part 3 - Battery Technology & Alternative Innovations (Korean)
E-mobility | Part 3 - Battery Technology & Alternative Innovations (Chinese)
E-mobility | Part 3 - Battery recycling & power electronics (English)
E-mobility | Part 2 - Battery Technology & Alternative Innovations (German)
E-mobility | Part 2 - Battery Technology & Alternative Innovations (Chinese)
E-mobility | Part 2 - Battery Technology & Alternative Innovations (Japanese)
E-mobility | Part 2 - Battery Technology & Alternative Innovations (Korean)

Recently uploaded (20)

PDF
TRAFFIC-MANAGEMENT-AND-ACCIDENT-INVESTIGATION-WITH-DRIVING-PDF-FILE.pdf
PPTX
oil_refinery_comprehensive_20250804084928 (1).pptx
PPTX
The THESIS FINAL-DEFENSE-PRESENTATION.pptx
PDF
“Getting Started with Data Analytics Using R – Concepts, Tools & Case Studies”
PDF
Recruitment and Placement PPT.pdfbjfibjdfbjfobj
PPTX
Acceptance and paychological effects of mandatory extra coach I classes.pptx
PPTX
Computer network topology notes for revision
PPTX
STUDY DESIGN details- Lt Col Maksud (21).pptx
PDF
Lecture1 pattern recognition............
PPTX
Introduction to Basics of Ethical Hacking and Penetration Testing -Unit No. 1...
PPTX
CEE 2 REPORT G7.pptxbdbshjdgsgjgsjfiuhsd
PPTX
MODULE 8 - DISASTER risk PREPAREDNESS.pptx
PPTX
Business Acumen Training GuidePresentation.pptx
PDF
Fluorescence-microscope_Botany_detailed content
PPTX
Introduction to Knowledge Engineering Part 1
PPT
Chapter 2 METAL FORMINGhhhhhhhjjjjmmmmmmmmm
PPTX
Major-Components-ofNKJNNKNKNKNKronment.pptx
PPT
Reliability_Chapter_ presentation 1221.5784
PPTX
Introduction to Firewall Analytics - Interfirewall and Transfirewall.pptx
PDF
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
TRAFFIC-MANAGEMENT-AND-ACCIDENT-INVESTIGATION-WITH-DRIVING-PDF-FILE.pdf
oil_refinery_comprehensive_20250804084928 (1).pptx
The THESIS FINAL-DEFENSE-PRESENTATION.pptx
“Getting Started with Data Analytics Using R – Concepts, Tools & Case Studies”
Recruitment and Placement PPT.pdfbjfibjdfbjfobj
Acceptance and paychological effects of mandatory extra coach I classes.pptx
Computer network topology notes for revision
STUDY DESIGN details- Lt Col Maksud (21).pptx
Lecture1 pattern recognition............
Introduction to Basics of Ethical Hacking and Penetration Testing -Unit No. 1...
CEE 2 REPORT G7.pptxbdbshjdgsgjgsjfiuhsd
MODULE 8 - DISASTER risk PREPAREDNESS.pptx
Business Acumen Training GuidePresentation.pptx
Fluorescence-microscope_Botany_detailed content
Introduction to Knowledge Engineering Part 1
Chapter 2 METAL FORMINGhhhhhhhjjjjmmmmmmmmm
Major-Components-ofNKJNNKNKNKNKronment.pptx
Reliability_Chapter_ presentation 1221.5784
Introduction to Firewall Analytics - Interfirewall and Transfirewall.pptx
168300704-gasification-ppt.pdfhghhhsjsjhsuxush

Data Protection and Privacy

  • 2. Source: European Union: ECJ Inv alidates Data Retention Directiv e by Theresa Papademetriou | EU General Data Protection Regulation and what it means f or SaaS companies in 2017 and 2018 by Megan Lozicki, Niklas Skog, Diego Checa | GDPR – Timeline by Bird & Bird | A v isual timeline f or implementing the GDPR in the UK EU Data Protection Reform The EU 1995 Data Protection Directive was archaic and non-legally binding for every member state; reform was necessary to improve data protection and privacy 1995: The Data Protection Directive (DPP), officially Directive 95/46/EC is passed. The directive establishes that the ownership of personal data belongs to individuals, who have legal rights over the collection and processing of personal data. 2000: The US-EU Safe Harbour Framework are created as an addition to the 1995 DPP. US companies that comply with the principles and register their certification, such that they fulfill EU requirements, are allowed to transfer data from the EU to the US. 2011: Viviane Reding, the VP of the European Commission, introduces the EU data protection reform. 2012: The legislative proposal of the new General Data Protection Regulation (GDPR) is published and negotiations begin amongst European parliaments. 2015: The Safe Harbour framework is invalidated by the CJEU as a result of the Schrems vs Data Protection Commissioner case. 2016: The new GDPR is approved on 14th April. The EU-US Privacy Shield framework is approved on 12th July, to replace the Safe Harbour agreement. 2018: The GDPR will officially replace the 1995 DPP on 25th May.
  • 3. General Data Protection Regulation The new regulation is expected to increase privacy for individuals and provide regulators with more power to take action against businesses in breach Extended Jurisdiction • Applies to all businesses processing personal data of data subjects who are in the EU, regardless of company location and where the processing is carried out Consent • Requests for consent must be intelligible and easily accessible, using clear and plain language • An affirmative action signalling consent is required • Consent should be as easily withdrawn as to give it • Requires parental consent for processing children’s personal data Right to Access • Data subjects have the right to obtain confirmation from the data controller as to whether their personal data is being processed, where and for what purpose Right to be Forgotten • Data subjects have the right to demand the data controller to erase their personal data, cease further dissemination of the data, and potentially have third parties halt processing of the data Breach Notification • Mandatory to notify authorities within 72 hours of first having become aware of a data breach • Data processors must notify their controllers Source: EU GDPR | Top 10 operational impacts of the GDPR: Part 1 – data security and breach notif ication by Rita Heimes | MANAGE THE TOP 4 GDPR OPERATIONAL IMPACTS (PART I) by Donna Recchione | MANAGE THE TOP 10 GDPR OPERATIONAL IMPACTS (PART II) by Donna Recchione
  • 4. General Data Protection Regulation Including hefty penalties for violations - fines of up to 4% of the company’s worldwide annual turnover or EUR 20M, whichever is higher Penalties for Violations • Fine up to 4% of the company’s worldwide annual turnover or EUR 20M, whichever is higher Cross-border Data Transfers • Personal data transfers permitted to a third country or international organization will be subject to compliance • In the absence of an adequacy decision, transfers are still allowed under certain circumstances, such as by use of standard contractual clauses or binding corporate rules Data Protection Officers • Large firms and companies that process specialized data must assign a qualified DPO for GDPR compliance Data Portability • Data subjects have the right to receive their personal data in a commonly used and machine readable format • They have the right to transmit that data to another controller Restricted Profiling • Data subjects have the right not to be subject to a decision based solely on automated processing, which produces legal effects or significantly affects them, without human intervention Source: EU GDPR | Top 10 operational impacts of the GDPR: Part 1 – data security and breach notif ication by Rita Heimes | MANAGE THE TOP 4 GDPR OPERATIONAL IMPACTS (PART I) by Donna Recchione | MANAGE THE TOP 10 GDPR OPERATIONAL IMPACTS (PART II) by Donna Recchione | Top 10 operational impacts of the GDPR: Part 4 - Cross-border data transf ers by Anna My ers
  • 5. Source: 2018 Tech Vendor Report by iapp Privacy Tech Industry Driving the need for an array of solutions to decisively address a slew of privacy compliance challenges Activity Monitoring Consent Manager Data Discovery Data Mapping Pseudonymity Enterprise Communications Incident Response Website Scanning Assessment Manager
  • 6. Privacy Tech Industry Leading to robust vendor growth and increase in solutions offered; with products targeting core compliance requirements accounting for >75% of the industry Source: 2018 Tech Vendor Report by iapp | 2017 Tech Vendor Report by iapp • Vendors are currently focusing on meeting core compliance requirements (via activity monitoring, assessment managers, consent managers, data discovery and data mapping) • Solutions targeting these areas make up 77% of the industry • They are integral to achieving primary regulatory compliance • Other aspects of privacy compliance remain largely untapped, presenting potential market opportunities for startups • The privacy tech industry is booming as evidenced by the robust vendor growth last year • Existing vendors have also built out new privacy technology services in the last year, adding to industry dynamics 43 51 67 98 122 0 20 40 60 80 100 120 140 Q1 2017 Q2 Q3 Q4 Q1 2018 Number of Vendors Website Scanning 4% Incident Response 8%Enterprise Communications 4% Pseudonymity 7% Data Mapping 19% Data Discovery 16% Consent Manager 11% Assessment Manager 16% Activity Monitoring 15%
  • 7. Looking Ahead • Reform of the archaic EU 1995 DPP was necessary to improve data protection and privacy • The new regulation is expected to increase privacy for individuals, provide regulators with more power to take action against businesses in breach • Complexity in managing data is driving the need for solutions to address privacy compliance challenges • Existing vendors are primarily focused on producing solutions revolving around assessment managers, activity monitoring, data discovery, data mapping, consent managers • Other aspects of privacy compliance remain largely untapped, presenting potential market opportunities for startups • Whilst most solutions target resolving compliance issues within client datacenters, a small minority have identified the need for data management in the cloud as well as in mobile applications • Privacy technology tools certainly look interesting but companies need to be careful as these external solutions may introduce new enterprise risks About Vertex Ventures Vertex Ventures is a global network of operator-investors who manage portfolios in the U.S., China, Israel, India and Southeast Asia. Vertex teams combine firsthand experience in transformational technologies; on-the-ground knowledge in the world’s major innovation centers; and global context, connections and customers. Yanai Oron General Partner Vertex Ventures Israel yanai@vertexventures.com