SlideShare a Scribd company logo
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com
GENERAL DATA PROTECTION REGULATION
(EU GDPR)
WHY SILICON VALLEY NEEDS TO GET IT RIGHT
MIRENA TASKOVA
1/14/2019 European Entrepreneurship & Innovation – Stanford School of Engineering
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com1
GDPR
Why am I here today? What will I learn?
Why the European Union GDPR matters
to US companies & consumers, and why
bother?
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com2
GDPR
Why am I here today? What will I learn?
What is personal data?
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com
3
GDPR
What constitutes personal data?
Our company’s annual
report
Your salary details Your medical information
Your name and date of
birth
NO YES YES
YES
Your anonymous response
to a survey question
MAYBE
Your photo or image on a
CCTV camera
YES
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com4
GDPR
What rights do data subjects have? This means you too.
I want to have
errors about me
corrected
I don’t want to
receive your
marketing letters
and promotions
I want to find out
what data you
have about me
and how you’re
using it
Does the right to
be forgotten
apply to me?
I want to be able to
take my data and
reuse it on other
platforms
Please stop using my data until
you’ve verified there is a
legitimate purpose
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com5
GDPR
Company Fines under GDPR
WHY WE NEED TO GET IT RIGHT
Infringements of rights, basic principles, and rules on international transfers:
• €20 million or 4% of the total worldwide turnover of the preceding
financial year (whichever is higher)
Failure to notify of data breaches:
• €10 million or 2% of the total worldwide turnover of the preceding
financial year (whichever is higher)
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com6
GDPR
Enforcement Actions in Europe | January 2019
Increase in Supervisory
Authorities’ activity
(local level & cross border)
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com7
GDPR
Enforcement | UK
ü The Information Commissioner’s Office (ICO) received 1792 breach notifications in June 2018,
compared with 367 in April 2018;
ü There have been a number of high profile breaches for which fines are possible such as British
Airways, the Conservative Party, and Facebook;
ü Supermarket chain Tesco has been fined £16.4 million by the Financial Conduct Authority for failing to
exercise due skill, care, and diligence in protecting customers against a cyber-attack (not awarded
under the GDPR);
ü The ICO, for the first time, issued its maximum fine of £500,000 against Equifax for its security breach
(not awarded under the GDPR).
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com8
GDPR
Enforcement | Germany
ü During the months May-July 2018, 111 data breach notifications were filed with the Data Protection
Commissioner in Berlin. In the same period in 2017, the authority received only 12 notifications;
ü The Bavarian State Authority for data protection announced random controls (audits) of companies
beginning September 2018;
ü Not aware of any sanctions under the GDPR yet. A sanction procedure takes some time to complete
due to the strict procedural rules.
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com9
GDPR
Enforcement | France
ü More than 600 notifications of data breaches have been received by the French DPA
involving about 15 million people - about 7 per day since May 25 2018;
ü Since May 25 2018, the French DPA has received 3767 complaints vs. 2294
complaints over the same period in 2017. This represents a 64% increase;
ü In regards to joint-actions (similar to US class action suits), two organizations have
filed complaints with the French DPA:
• “La Quadrature du Net” filed 5 separate complaints over “forced consent” against
Google, Amazon, Facebook and Apple;
• The association “NOYB” filed a complaint over “forced consent” against Google
(Android).
ü Not aware of sanctions under the GDPR yet.
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com10
GDPR
This is just the beginning …
On November 8, 2018 Privacy
International filed complaints
against seven data brokers (Acxiom,
Oracle), ad-tech companies (Criteo,
Quantcast, Tapad), and credit
referencing agencies (Equifax,
Experian) with data protection
authorities in France, Ireland, and
the UK.
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com11
GDPR
This is just the beginning …
noyb filed four complaints over “forced
consent” against Google, Instagram,
WhatsApp and Facebook. The complaints
were filed with DPAs in Austria, Belgium,
France and Germany right after GDPR
came into force.
Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com12
GDPR
Questions?
Mirena Taskova - EU GDPR Intro & Update - Stanford Engineering - 14 Jan 2019
Mirena Taskova, CIPP/E
Senior Privacy Advisor
M: +1 (650) 250 3615
E: mirena.taskova@fieldfisher.com
Follow: @Fieldfisher
www.linkedin.com/in/mirenataskova
Blog: privacylawblog.fieldfisher.com

More Related Content

PPTX
Ipswitch and cordery on the road " All you need to know about GDPR but are t...
PDF
I have listed 3 informative youtube videos on the eu gdpr
PPTX
Everything you need to know about the GDPR
PPTX
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
PPTX
One year of GDPR, what happened and what to expect!
PDF
EU General Data Protection Regulation
PPTX
The EU Data Protection Regulation - what you need to know
PPTX
Matthew Hough Clewes | Cyber Crime and its Impacts
Ipswitch and cordery on the road " All you need to know about GDPR but are t...
I have listed 3 informative youtube videos on the eu gdpr
Everything you need to know about the GDPR
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
One year of GDPR, what happened and what to expect!
EU General Data Protection Regulation
The EU Data Protection Regulation - what you need to know
Matthew Hough Clewes | Cyber Crime and its Impacts

What's hot (14)

PDF
ESET Quick Guide to the EU General Data Protection Regulation
PDF
Datum DPO outsourced May 2016
PDF
20210526 cybersafety first! Sirius Legal webinar for Comeos
PDF
EU-US Privacy Shield - Safe Harbor Replacement
PPTX
I4ADA 2019 - Presentation Jeff Bullwinkel
PPT
Sson amsterdam may 2012 roundtable - mark lewis berwin leighton paisner
PPTX
EU GDPR: The role of the data protection officer
PPTX
GDPR How ready are you? The What, Why and How.
PDF
General Data Protection Regulation: what do you need to do to get prepared? -...
PPTX
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
PPTX
Facing the Big Data Revolution: A German Perspective
PPTX
GDPR: More reasons for information security
PDF
GDPR - GoDataFest - October 16 - Juliette van Baalen
PDF
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
ESET Quick Guide to the EU General Data Protection Regulation
Datum DPO outsourced May 2016
20210526 cybersafety first! Sirius Legal webinar for Comeos
EU-US Privacy Shield - Safe Harbor Replacement
I4ADA 2019 - Presentation Jeff Bullwinkel
Sson amsterdam may 2012 roundtable - mark lewis berwin leighton paisner
EU GDPR: The role of the data protection officer
GDPR How ready are you? The What, Why and How.
General Data Protection Regulation: what do you need to do to get prepared? -...
#FIRMday Manchester Autumn 2017 - The General Data Protection Regulation (GDP...
Facing the Big Data Revolution: A German Perspective
GDPR: More reasons for information security
GDPR - GoDataFest - October 16 - Juliette van Baalen
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
Ad

Similar to Mirena Taskova - EU GDPR Intro & Update - Stanford Engineering - 14 Jan 2019 (20)

PPT
Lexing Barcelona Conference
PDF
Infographic–A Look Back at the First Year of GDPR
PDF
http://www.slideshare.net/slideshow/embed_code/28627951
PPTX
Jisc GDPR conference
PDF
GDPR - Applift firstscreen june 2016
PPTX
Legal Implications of a Cyber Attack
PDF
A Pratical Guide to GDPR - F.Coin
PDF
Leila Golchehreh - Adaptive Insights - Intro to New EU GDPR Data Privacy Rule...
PDF
CASE STUDY: New EU legislation: how to avoid data disaster
PPTX
Board Priorities for GDPR Implementation
DOCX
Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
PDF
GDPR: A Threat or Opportunity? www.normanbroadbent.
PPTX
GDPR training
 
PDF
Data Protection Predictions for 2023.pdf
PDF
For Superweek 2022: discussing risk using IAB's TCF
PPTX
Data protection & security breakfast briefing master slides 28 june-final
PPTX
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
PDF
GDPR: What UK SMBs should know
PDF
Dla piper data breach report 2020
PDF
Are you prepared for information compliance
Lexing Barcelona Conference
Infographic–A Look Back at the First Year of GDPR
http://www.slideshare.net/slideshow/embed_code/28627951
Jisc GDPR conference
GDPR - Applift firstscreen june 2016
Legal Implications of a Cyber Attack
A Pratical Guide to GDPR - F.Coin
Leila Golchehreh - Adaptive Insights - Intro to New EU GDPR Data Privacy Rule...
CASE STUDY: New EU legislation: how to avoid data disaster
Board Priorities for GDPR Implementation
Running Head THE IMPACT OF GDPR ON GLOBAL IT POLICIES1THE IMPA.docx
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR training
 
Data Protection Predictions for 2023.pdf
For Superweek 2022: discussing risk using IAB's TCF
Data protection & security breakfast briefing master slides 28 june-final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
GDPR: What UK SMBs should know
Dla piper data breach report 2020
Are you prepared for information compliance
Ad

More from Burton Lee (20)

PDF
Santiago Bassett - Wazuh - Growing Cybersecurity Startups in Granada & Silico...
PDF
Julio Casal - 4iQ & AlienVault - Viaje de un Cybersecurity Startup a Silicon ...
PDF
Burton Lee - Session #7 - Madrid + Granada - Cybersecurity Startups - Spanish...
PDF
Peter Fatelnig - EU Delegation to USA - Content Matters & EU Leadership - Sta...
PDF
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
PDF
Dejan Roljic - Eligma - Growing Bitcoin Cities from Slovenia - Stanford Engin...
PDF
Burton Lee - Session #6 Intro - Bitcoin Cities | GDPR & Stasi Files - Stanfor...
PDF
Burton Lee - Session #5 Intro - European Corporate Venture Capital - Stanford...
PDF
Elif Ceylan - ITU ARI Teknokent & Innogate - University Accelerators in Turke...
PDF
Ege Ertem - Zorlu Ventures - Family Enterprises in Turkey - Stanford Engineer...
PDF
Miray Tayfun - Vivoo - Wellness Startups in Turkey & Silicon Valley - Stanfor...
PDF
Burton Lee - Session #4 - Turkey Innovation Ecosystem - Stanford Engineering ...
PDF
Nathalie Delrue-McGuire - Belgium, Flanders & Belcham USA - Stanford Engineer...
PDF
Dirk Wauters - Flanders & Leuven Tech Ecosystem - Stanford Engineering - 28 J...
PDF
Hendrik Isebaert - Showpad & Ghent - Enterprise Software in Flanders - Stanfo...
PDF
Burton Lee - Session #3 - Flanders :: From WW1 to Global Leadership in Enterp...
PDF
Burton Lee - Session #2 - Berlin Mobile Banking Unicorns & GDPR Update - Stan...
PDF
Burton Lee - Course Intro & Session #1 - Czechia & CEE Ecosystem - Stanford M...
PDF
Burton Lee - AI and Remote Diagnostics of Factory Equipment - IHK München 175...
PDF
Burton Lee - Session #8 Intro - Stanford ME421 - Mar 12 2018 - Part 1
Santiago Bassett - Wazuh - Growing Cybersecurity Startups in Granada & Silico...
Julio Casal - 4iQ & AlienVault - Viaje de un Cybersecurity Startup a Silicon ...
Burton Lee - Session #7 - Madrid + Granada - Cybersecurity Startups - Spanish...
Peter Fatelnig - EU Delegation to USA - Content Matters & EU Leadership - Sta...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Dejan Roljic - Eligma - Growing Bitcoin Cities from Slovenia - Stanford Engin...
Burton Lee - Session #6 Intro - Bitcoin Cities | GDPR & Stasi Files - Stanfor...
Burton Lee - Session #5 Intro - European Corporate Venture Capital - Stanford...
Elif Ceylan - ITU ARI Teknokent & Innogate - University Accelerators in Turke...
Ege Ertem - Zorlu Ventures - Family Enterprises in Turkey - Stanford Engineer...
Miray Tayfun - Vivoo - Wellness Startups in Turkey & Silicon Valley - Stanfor...
Burton Lee - Session #4 - Turkey Innovation Ecosystem - Stanford Engineering ...
Nathalie Delrue-McGuire - Belgium, Flanders & Belcham USA - Stanford Engineer...
Dirk Wauters - Flanders & Leuven Tech Ecosystem - Stanford Engineering - 28 J...
Hendrik Isebaert - Showpad & Ghent - Enterprise Software in Flanders - Stanfo...
Burton Lee - Session #3 - Flanders :: From WW1 to Global Leadership in Enterp...
Burton Lee - Session #2 - Berlin Mobile Banking Unicorns & GDPR Update - Stan...
Burton Lee - Course Intro & Session #1 - Czechia & CEE Ecosystem - Stanford M...
Burton Lee - AI and Remote Diagnostics of Factory Equipment - IHK München 175...
Burton Lee - Session #8 Intro - Stanford ME421 - Mar 12 2018 - Part 1

Recently uploaded (20)

PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Cloud computing and distributed systems.
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPT
Teaching material agriculture food technology
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Machine learning based COVID-19 study performance prediction
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Approach and Philosophy of On baking technology
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
Unlocking AI with Model Context Protocol (MCP)
Empathic Computing: Creating Shared Understanding
Cloud computing and distributed systems.
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Reach Out and Touch Someone: Haptics and Empathic Computing
Teaching material agriculture food technology
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Machine learning based COVID-19 study performance prediction
Mobile App Security Testing_ A Comprehensive Guide.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
The AUB Centre for AI in Media Proposal.docx
Approach and Philosophy of On baking technology
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Chapter 3 Spatial Domain Image Processing.pdf

Mirena Taskova - EU GDPR Intro & Update - Stanford Engineering - 14 Jan 2019

  • 1. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com GENERAL DATA PROTECTION REGULATION (EU GDPR) WHY SILICON VALLEY NEEDS TO GET IT RIGHT MIRENA TASKOVA 1/14/2019 European Entrepreneurship & Innovation – Stanford School of Engineering
  • 2. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com1 GDPR Why am I here today? What will I learn? Why the European Union GDPR matters to US companies & consumers, and why bother?
  • 3. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com2 GDPR Why am I here today? What will I learn? What is personal data?
  • 4. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com 3 GDPR What constitutes personal data? Our company’s annual report Your salary details Your medical information Your name and date of birth NO YES YES YES Your anonymous response to a survey question MAYBE Your photo or image on a CCTV camera YES
  • 5. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com4 GDPR What rights do data subjects have? This means you too. I want to have errors about me corrected I don’t want to receive your marketing letters and promotions I want to find out what data you have about me and how you’re using it Does the right to be forgotten apply to me? I want to be able to take my data and reuse it on other platforms Please stop using my data until you’ve verified there is a legitimate purpose
  • 6. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com5 GDPR Company Fines under GDPR WHY WE NEED TO GET IT RIGHT Infringements of rights, basic principles, and rules on international transfers: • €20 million or 4% of the total worldwide turnover of the preceding financial year (whichever is higher) Failure to notify of data breaches: • €10 million or 2% of the total worldwide turnover of the preceding financial year (whichever is higher)
  • 7. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com6 GDPR Enforcement Actions in Europe | January 2019 Increase in Supervisory Authorities’ activity (local level & cross border)
  • 8. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com7 GDPR Enforcement | UK ü The Information Commissioner’s Office (ICO) received 1792 breach notifications in June 2018, compared with 367 in April 2018; ü There have been a number of high profile breaches for which fines are possible such as British Airways, the Conservative Party, and Facebook; ü Supermarket chain Tesco has been fined £16.4 million by the Financial Conduct Authority for failing to exercise due skill, care, and diligence in protecting customers against a cyber-attack (not awarded under the GDPR); ü The ICO, for the first time, issued its maximum fine of £500,000 against Equifax for its security breach (not awarded under the GDPR).
  • 9. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com8 GDPR Enforcement | Germany ü During the months May-July 2018, 111 data breach notifications were filed with the Data Protection Commissioner in Berlin. In the same period in 2017, the authority received only 12 notifications; ü The Bavarian State Authority for data protection announced random controls (audits) of companies beginning September 2018; ü Not aware of any sanctions under the GDPR yet. A sanction procedure takes some time to complete due to the strict procedural rules.
  • 10. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com9 GDPR Enforcement | France ü More than 600 notifications of data breaches have been received by the French DPA involving about 15 million people - about 7 per day since May 25 2018; ü Since May 25 2018, the French DPA has received 3767 complaints vs. 2294 complaints over the same period in 2017. This represents a 64% increase; ü In regards to joint-actions (similar to US class action suits), two organizations have filed complaints with the French DPA: • “La Quadrature du Net” filed 5 separate complaints over “forced consent” against Google, Amazon, Facebook and Apple; • The association “NOYB” filed a complaint over “forced consent” against Google (Android). ü Not aware of sanctions under the GDPR yet.
  • 11. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com10 GDPR This is just the beginning … On November 8, 2018 Privacy International filed complaints against seven data brokers (Acxiom, Oracle), ad-tech companies (Criteo, Quantcast, Tapad), and credit referencing agencies (Equifax, Experian) with data protection authorities in France, Ireland, and the UK.
  • 12. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com11 GDPR This is just the beginning … noyb filed four complaints over “forced consent” against Google, Instagram, WhatsApp and Facebook. The complaints were filed with DPAs in Austria, Belgium, France and Germany right after GDPR came into force.
  • 13. Belgium | China | France | Germany | Italy | Netherlands | UK | US (Silicon Valley) | fieldfisher.com12 GDPR Questions?
  • 15. Mirena Taskova, CIPP/E Senior Privacy Advisor M: +1 (650) 250 3615 E: mirena.taskova@fieldfisher.com Follow: @Fieldfisher www.linkedin.com/in/mirenataskova Blog: privacylawblog.fieldfisher.com