SlideShare a Scribd company logo
General Data Protection Regulation - GDPR
GDPR – Strategic Change
▶ Ownership
▶ Priorities
▶ Communication
▶ Risk
▶ Time
▶ Cost
▶ Opportunity
Biometric
Data
Vehicle
Regn
IP
Address
Passport
Number
NI
Number
Email
Address
Full
Name
First
Name
Last
Name
Login
Details
(username)
Postcode
Genetic
Info
Birthplace
Date of
Birth
Digital
Identity
Credit
Card No
Telephone
No Workplace
Drivers
Licence
No
Cookies
Criminal
Record
Salary
Gender
Age
It’s all of the above
TIME
Awareness of
GDPR
Attend Public GDPR
events
Daunted by the scale of
GDPR
Start small with focused
workshop or live project
Implement a company
specific programme
Competitive Advantage curve
Early Adopters Early Majority Late Majority Laggards
Shock
Denial
Frustration
Depression
Experiment
Decision
Change success
Change curve
GDPR Workshop
Typical questions for discussion
• What consent do I need?
• Do I need to get opt-in permission for existing
customers/prospects?
• What is legitimate interest?
• When do I have to be compliant?
• What data is included?
• How do I secure data in cloud software?
• What is the difference between business and personal data?
• How can I store data?
• What if I have printed data?
• Who owns the data?
• What level of security is needed for data and emails?
• What are my responsibilities for data shared with my supply chain?
• How can I do telemarketing?
• What is the impact for payroll and pensions for staff?
• What are the likely fines?
• How do I handle subject access requests and the confirmation of
identity?
• What level of education do I need for the company?
Breach Management
▶ Produce an incident management plan
▶ Communicate the plan to all staff
▶ Inform the team who to contact if they have concerns
▶ Ensure that all your suppliers / data processors have an equivalent plan (and that their teams
know about it)
▶ As controller you must ensure processors report any breach without delay
▶ Damage limitation on your brand / reputation
▶ Real life risks – malicious intent, human error, ambulance chasing,…
If you take one action away today we
would recommend starting with the
simple process outlined here to follow
data into your company to see:
• What personal data is taken?
• Who touches it?
• What gets done with it?
• Where is it stored?
One off meeting 1/2 days per week 3/4 days per week
Augmentum managed √
Company managed √
Augmentum managed √
Company managed √
Augmentum managed √
Company managed √
Project Governance √ √ √
Project strategy initiation to include data
mapping requirements, process review,
project communication, budget planning,
resource skill and availability
√ √ √
Project initiation and audit pilot /project to
complete data/process mapping. Process
assessment and adjustment
√ √√? √
Data policy drafting and sign off. Staff
communication, training. Consent wording
for all data capture methods
√ √√? √
Engaging/managing external experts for
legal, IT, etc √ √√? √
Supply chain requirements and contract
implementation √ √√? √
Project testing and review
√ √√? √
Ongoing review and audit √ √ √
GDPR services
The complex nature of GDPR projects requires the right initiation which will then advise on the budget and resources
required to work towards compliance. The matrix has been designed to give an oversight of the elements and a
recognition that there will be a mix of internal and external resources required.

More Related Content

PPTX
Payroll Data & GDPR: What you need to know?
PPTX
General Data Protection Regulation (GDPR)
PDF
Gdpr overview ciso platform presentation
PPTX
Teradata's approach to addressing GDPR
PDF
GDPR changes affect direct marketing
PDF
Everything you Need to Know about The Data Protection Officer Role
PPTX
GDPR security services - Areyou ready ?
PPTX
GDPR - Fail to Prepare, Prepare to Fail!
Payroll Data & GDPR: What you need to know?
General Data Protection Regulation (GDPR)
Gdpr overview ciso platform presentation
Teradata's approach to addressing GDPR
GDPR changes affect direct marketing
Everything you Need to Know about The Data Protection Officer Role
GDPR security services - Areyou ready ?
GDPR - Fail to Prepare, Prepare to Fail!

What's hot (18)

PPTX
GDPR and NIS Compliance - How HyTrust Can Help
PDF
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
PPTX
GDPR practical info session for development
PDF
20170323 are you ready the new gdpr is here
PDF
CyNation - 7 things you should know about EU-GDPR
PDF
7 Key GDPR Requirements & the Role of Data Governance
PDF
DAMA Ireland - GDPR
PDF
GDPR Cyber Insurance 11/1/2017
PPTX
General Data Protection Regulation
PDF
Data Flow Mapping and the EU GDPR
PDF
GDPR 11/1/2017
PPTX
Vuzion Love Cloud GDPR Event
PDF
2016 11-17-gdpr-integro-webinar
PDF
How IBM Supports Clients around GDPR and Cybersecurity Legislation
PDF
GDPR what you should know and how to minimize impact on your business
PDF
Preparing for EU GDPR
PDF
CyNation: 7 Things You Should Know about EU GDPR
PDF
Data Flow Mapping and the EU GDPR
GDPR and NIS Compliance - How HyTrust Can Help
Privacy_Engineering_Privacy Assurance_Lecture-Ecole_Polytechnic_Nice_SA-20150127
GDPR practical info session for development
20170323 are you ready the new gdpr is here
CyNation - 7 things you should know about EU-GDPR
7 Key GDPR Requirements & the Role of Data Governance
DAMA Ireland - GDPR
GDPR Cyber Insurance 11/1/2017
General Data Protection Regulation
Data Flow Mapping and the EU GDPR
GDPR 11/1/2017
Vuzion Love Cloud GDPR Event
2016 11-17-gdpr-integro-webinar
How IBM Supports Clients around GDPR and Cybersecurity Legislation
GDPR what you should know and how to minimize impact on your business
Preparing for EU GDPR
CyNation: 7 Things You Should Know about EU GDPR
Data Flow Mapping and the EU GDPR
Ad

Similar to GDPR Workshop (20)

PDF
#HR and #GDPR: Preparing for 2018 Compliance
PDF
Gdpr for business full
PPTX
GDPR How to get started?
PDF
What's Next - General Data Protection Regulation (GDPR) Changes
PDF
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
PDF
General Data Protection Regulation, a developer's story
PDF
Enterprise Data World 2018
PPTX
GDPR in the Healthcare Industry
PDF
GDPR- The Buck Stops Here
PDF
GDPR (En) JM Tyszka
PDF
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
PDF
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
PDF
GDPR - Sink or Swim
PPTX
Keep Calm and Comply: 3 Keys to GDPR Success
PPTX
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
PPTX
Ritz 4th-july-gdpr
PDF
Gdpr presentation
PDF
GDPR Checklist Infographic
PPTX
Ready for the GDPR, Ready for the Digital Economy
PPTX
GDPR: Your Journey to Compliance
#HR and #GDPR: Preparing for 2018 Compliance
Gdpr for business full
GDPR How to get started?
What's Next - General Data Protection Regulation (GDPR) Changes
Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regu...
General Data Protection Regulation, a developer's story
Enterprise Data World 2018
GDPR in the Healthcare Industry
GDPR- The Buck Stops Here
GDPR (En) JM Tyszka
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
[Srijan Wednesday Webinars] Is Your Business Ready for GDPR
GDPR - Sink or Swim
Keep Calm and Comply: 3 Keys to GDPR Success
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
Ritz 4th-july-gdpr
Gdpr presentation
GDPR Checklist Infographic
Ready for the GDPR, Ready for the Digital Economy
GDPR: Your Journey to Compliance
Ad

Recently uploaded (20)

PDF
Business model innovation report 2022.pdf
PPTX
New Microsoft PowerPoint Presentation - Copy.pptx
DOCX
Euro SEO Services 1st 3 General Updates.docx
PDF
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
PDF
DOC-20250806-WA0002._20250806_112011_0000.pdf
PPTX
Probability Distribution, binomial distribution, poisson distribution
PPTX
HR Introduction Slide (1).pptx on hr intro
PPTX
5 Stages of group development guide.pptx
PDF
A Brief Introduction About Julia Allison
PPTX
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
PDF
MSPs in 10 Words - Created by US MSP Network
PDF
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
PPTX
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
PPTX
Amazon (Business Studies) management studies
PDF
Roadmap Map-digital Banking feature MB,IB,AB
PDF
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
DOCX
Business Management - unit 1 and 2
PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PDF
Reconciliation AND MEMORANDUM RECONCILATION
PDF
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi
Business model innovation report 2022.pdf
New Microsoft PowerPoint Presentation - Copy.pptx
Euro SEO Services 1st 3 General Updates.docx
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
DOC-20250806-WA0002._20250806_112011_0000.pdf
Probability Distribution, binomial distribution, poisson distribution
HR Introduction Slide (1).pptx on hr intro
5 Stages of group development guide.pptx
A Brief Introduction About Julia Allison
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
MSPs in 10 Words - Created by US MSP Network
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
Amazon (Business Studies) management studies
Roadmap Map-digital Banking feature MB,IB,AB
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
Business Management - unit 1 and 2
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
Reconciliation AND MEMORANDUM RECONCILATION
pdfcoffee.com-opt-b1plus-sb-answers.pdfvi

GDPR Workshop

  • 1. General Data Protection Regulation - GDPR
  • 2. GDPR – Strategic Change ▶ Ownership ▶ Priorities ▶ Communication ▶ Risk ▶ Time ▶ Cost ▶ Opportunity
  • 4. TIME Awareness of GDPR Attend Public GDPR events Daunted by the scale of GDPR Start small with focused workshop or live project Implement a company specific programme Competitive Advantage curve Early Adopters Early Majority Late Majority Laggards Shock Denial Frustration Depression Experiment Decision Change success Change curve
  • 6. Typical questions for discussion • What consent do I need? • Do I need to get opt-in permission for existing customers/prospects? • What is legitimate interest? • When do I have to be compliant? • What data is included? • How do I secure data in cloud software? • What is the difference between business and personal data? • How can I store data? • What if I have printed data? • Who owns the data? • What level of security is needed for data and emails? • What are my responsibilities for data shared with my supply chain? • How can I do telemarketing? • What is the impact for payroll and pensions for staff? • What are the likely fines? • How do I handle subject access requests and the confirmation of identity? • What level of education do I need for the company?
  • 7. Breach Management ▶ Produce an incident management plan ▶ Communicate the plan to all staff ▶ Inform the team who to contact if they have concerns ▶ Ensure that all your suppliers / data processors have an equivalent plan (and that their teams know about it) ▶ As controller you must ensure processors report any breach without delay ▶ Damage limitation on your brand / reputation ▶ Real life risks – malicious intent, human error, ambulance chasing,…
  • 8. If you take one action away today we would recommend starting with the simple process outlined here to follow data into your company to see: • What personal data is taken? • Who touches it? • What gets done with it? • Where is it stored?
  • 9. One off meeting 1/2 days per week 3/4 days per week Augmentum managed √ Company managed √ Augmentum managed √ Company managed √ Augmentum managed √ Company managed √ Project Governance √ √ √ Project strategy initiation to include data mapping requirements, process review, project communication, budget planning, resource skill and availability √ √ √ Project initiation and audit pilot /project to complete data/process mapping. Process assessment and adjustment √ √√? √ Data policy drafting and sign off. Staff communication, training. Consent wording for all data capture methods √ √√? √ Engaging/managing external experts for legal, IT, etc √ √√? √ Supply chain requirements and contract implementation √ √√? √ Project testing and review √ √√? √ Ongoing review and audit √ √ √ GDPR services The complex nature of GDPR projects requires the right initiation which will then advise on the budget and resources required to work towards compliance. The matrix has been designed to give an oversight of the elements and a recognition that there will be a mix of internal and external resources required.