GDPR
OVERVIEW:
KEYS TO
READINESS
THE EUROPEAN UNION (EU)
IS IMPLEMENTING THE
GENERAL DATA PROTECTION
REGULATION (GDPR) THAT
TAKES EFFECT MAY 2018.
2018
GDPR EXECUTIVE OVERVIEW
GENERAL DATA PROTECTION REGULATION
2
The objective of the GDPR is harmonization of EU regulations to enhance
the rights of EU citizens to govern the privacy of their personal information
and ensure organizations provide the right protections.
The GDPR applies to EU and non-EU organizations that:
(i) offer goods or services to EU residents;
(ii) monitor the behavior of EU residents
The GDPR effective date:
 May 25, 2018
Penalties:
 Up to 20,000,000 EUR or 4% worldwide revenue from the previous
fiscal year (Article 83). Fines are determined by the Data Protection
Authority (Supervisory Authority).
* The “Articles” referenced in this document refer to the articles included in the GDPR regulation. A
link to the regulation text is included in the Appendix section of this document.
GDPR EXECUTIVE OVERVIEW
GDPR CONCEPTS
3
Principles, privacy, and protection represent the core focus for GDPR readiness.
Organizations must focus on adhering to principles, implementing processes to
satisfy privacy rights of the individual, and securing data.
Principles
 Data processed lawfully, fairly, and transparently
 Only collect personal data needed
 Accuracy of personal data must be maintained
 Minimize the time data is kept in a form to
identify data subjects
 Maintain the confidentiality and integrity of
personal data
Privacy (rights of data subjects)
 Transparent information, communication and
modalities for the exercise of the rights of the
data subject
 Information to be provided where personal data
are collected from the data subject
 Right of access by the data subject
 Right to rectification
 Right to erasure (‘right to be forgotten’)
 Right to restriction of processing
 Right to data portability
Protection (controllers and
processors)
 Data Protection Officer (DPO)
 Data protection by design
 Records of processing activities
 Security of processing
 Notification of a personal data breach to the
supervisory authority
 Communication of a personal data breach to the
data subject
 Data protection impact assessment
 Code of conduct
GDPR EXECUTIVE OVERVIEW
EXECUTION
4
GDPR requires the organization to address privacy and security of personal
data. A proven approach to gaining clarity on GDPR relevance and
understanding how to execute is described below. The Data Protection
Officer (DPO) must lead the effort to achieve and maintain alignment.
Preparation
• Assign data privacy
ownership
• Understand the
regulation
Assessment
• Understand the risk
of activities
• Perform Readiness
Assessment
Implementation
• Inform the
Organization
• Address consent
• Address rights of
the individual
• Protect personal
data
Maintenance
• Operationalize
GDPR controls
GDPR EXECUTIVE OVERVIEW
KEY CONSIDERATIONS
5
GDPR readiness can be complex for some organizations. Leadership should
begin to prepare the organization for the journey.
1. Key is establishing the DPO role (internal or external)
2. Gain clarity on the organization’s responsibility
3. Complying with rights of the individual is not trivial – business processes,
service desk, and technology impacts. Factor effort into 2018 budget –
resource impact is key consideration (assuming good security practices).
4. Processor assessment is key – liability isn’t shifted to the processor
5. Certification is not defined and is not required. DPA (supervisory
authority) will assign certification bodies and certification guidelines.
Move forward with readiness while tracking DPA guidance.
GDPR EXECUTIVE OVERVIEW
GDPR MISPERCEPTIONS
6
Understanding GDPR requirements can be complex. There are several
common misperceptions that should be clarified.
1. A Data Protection Officer is required for all organizations
2. Each GDPR incident will carry a fine equivalent to the greater of 20 mil Euro
or 4% annual worldwide revenue
3. Consent is always required for processing of personal data
4. Parental consent is always required when collecting personal information
from a child
5. Individuals have the absolute right to be forgotten
6. Biometric data is sensitive data
7. Controllers do not require processing agreements with processors – GDPR
takes care of this

More Related Content

PDF
Gdpr and ISMS Quick Map Framework EL
PDF
GDPR 101
PDF
GDPR for Non-European Region - Financial Services EL
PDF
GDPR
PPTX
Introduction to GDPR
PDF
GDPR is Coming, Five Things You Can Do Now To Prepare
PDF
Complete Guide to General Data Protection Regulation (GDPR)
Gdpr and ISMS Quick Map Framework EL
GDPR 101
GDPR for Non-European Region - Financial Services EL
GDPR
Introduction to GDPR
GDPR is Coming, Five Things You Can Do Now To Prepare
Complete Guide to General Data Protection Regulation (GDPR)

What's hot (20)

PDF
Introduction to gdpr
PDF
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
PDF
EY General Data Protection Regulation: Are you ready?
PPTX
Data Protection: Transitioning to the GDPR
PDF
The Definitive GDPR Guide for Event Professionals
PPTX
Payslip gdpr deck nov 2017
PDF
The Essential Guide to GDPR
PPTX
What is GDPR?
PDF
Employee Training is Key to GDPR Compliance: GDPR
PDF
GDPR in a nutshell
PPTX
GDPR SECURITY ISSUES
PDF
Datum DPO outsourced May 2016
PDF
Are You Prepared for the GDPR?
PPTX
Data protection
PPTX
Cobb Digital Bitesize workshop - GDPR, are you compliant?
PDF
Talk1 esc7 muscl-gdpr_debate_v1_2
PPTX
An Overview of GDPR
PPTX
Taking the Fear Out of GDPR
PDF
General Data Protection Regulation: what do you need to do to get prepared? -...
PPTX
GDPR Data Lifecycle
Introduction to gdpr
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
EY General Data Protection Regulation: Are you ready?
Data Protection: Transitioning to the GDPR
The Definitive GDPR Guide for Event Professionals
Payslip gdpr deck nov 2017
The Essential Guide to GDPR
What is GDPR?
Employee Training is Key to GDPR Compliance: GDPR
GDPR in a nutshell
GDPR SECURITY ISSUES
Datum DPO outsourced May 2016
Are You Prepared for the GDPR?
Data protection
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Talk1 esc7 muscl-gdpr_debate_v1_2
An Overview of GDPR
Taking the Fear Out of GDPR
General Data Protection Regulation: what do you need to do to get prepared? -...
GDPR Data Lifecycle
Ad

Similar to Satori GDPR Overview 2018 (20)

PPTX
GDPR Enforcement is here. Are you ready?
PPTX
What is the General Data Protection Regulation (GDPR)?
PPTX
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
PPTX
GDPR How to get started?
PPTX
My presentation- Ala about privacy and GDPR
PDF
GDPR: What does it mean for your business?
PDF
#HR and #GDPR: Preparing for 2018 Compliance
PDF
GDPRIBMWhitePaper
PDF
The Countdown to the GDPR Regulations
PDF
Introduction to EU General Data Protection Regulation: Planning, Implementati...
PPTX
ABM Display Advertising Success in the World of GDPR [PPT]
PPTX
GDPR: Are you Ready?
PPTX
EU GDPR(general data protection regulation)
PDF
Aon GDPR white paper
PDF
Introduction to EU General Data Protection Regulation: Planning, Implementat...
PDF
GDPR: What does it mean for your business?
PDF
GDPR-Overview
PDF
GDPR all concerned! Essential Issues of the General Data Protection Regulatio...
PPTX
What does GDPR mean for your business?
PPTX
Vuzion Love Cloud GDPR Event
GDPR Enforcement is here. Are you ready?
What is the General Data Protection Regulation (GDPR)?
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR How to get started?
My presentation- Ala about privacy and GDPR
GDPR: What does it mean for your business?
#HR and #GDPR: Preparing for 2018 Compliance
GDPRIBMWhitePaper
The Countdown to the GDPR Regulations
Introduction to EU General Data Protection Regulation: Planning, Implementati...
ABM Display Advertising Success in the World of GDPR [PPT]
GDPR: Are you Ready?
EU GDPR(general data protection regulation)
Aon GDPR white paper
Introduction to EU General Data Protection Regulation: Planning, Implementat...
GDPR: What does it mean for your business?
GDPR-Overview
GDPR all concerned! Essential Issues of the General Data Protection Regulatio...
What does GDPR mean for your business?
Vuzion Love Cloud GDPR Event
Ad

Recently uploaded (20)

PDF
Hindi spoken digit analysis for native and non-native speakers
DOCX
search engine optimization ppt fir known well about this
PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
WOOl fibre morphology and structure.pdf for textiles
PPTX
Modernising the Digital Integration Hub
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
A review of recent deep learning applications in wood surface defect identifi...
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PPTX
Benefits of Physical activity for teenagers.pptx
PPTX
O2C Customer Invoices to Receipt V15A.pptx
PDF
Hybrid model detection and classification of lung cancer
PPT
What is a Computer? Input Devices /output devices
PDF
A novel scalable deep ensemble learning framework for big data classification...
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
PDF
Developing a website for English-speaking practice to English as a foreign la...
Hindi spoken digit analysis for native and non-native speakers
search engine optimization ppt fir known well about this
Getting started with AI Agents and Multi-Agent Systems
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
Group 1 Presentation -Planning and Decision Making .pptx
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
WOOl fibre morphology and structure.pdf for textiles
Modernising the Digital Integration Hub
DP Operators-handbook-extract for the Mautical Institute
A review of recent deep learning applications in wood surface defect identifi...
Zenith AI: Advanced Artificial Intelligence
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
Benefits of Physical activity for teenagers.pptx
O2C Customer Invoices to Receipt V15A.pptx
Hybrid model detection and classification of lung cancer
What is a Computer? Input Devices /output devices
A novel scalable deep ensemble learning framework for big data classification...
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
Developing a website for English-speaking practice to English as a foreign la...

Satori GDPR Overview 2018

  • 1. GDPR OVERVIEW: KEYS TO READINESS THE EUROPEAN UNION (EU) IS IMPLEMENTING THE GENERAL DATA PROTECTION REGULATION (GDPR) THAT TAKES EFFECT MAY 2018. 2018
  • 2. GDPR EXECUTIVE OVERVIEW GENERAL DATA PROTECTION REGULATION 2 The objective of the GDPR is harmonization of EU regulations to enhance the rights of EU citizens to govern the privacy of their personal information and ensure organizations provide the right protections. The GDPR applies to EU and non-EU organizations that: (i) offer goods or services to EU residents; (ii) monitor the behavior of EU residents The GDPR effective date:  May 25, 2018 Penalties:  Up to 20,000,000 EUR or 4% worldwide revenue from the previous fiscal year (Article 83). Fines are determined by the Data Protection Authority (Supervisory Authority). * The “Articles” referenced in this document refer to the articles included in the GDPR regulation. A link to the regulation text is included in the Appendix section of this document.
  • 3. GDPR EXECUTIVE OVERVIEW GDPR CONCEPTS 3 Principles, privacy, and protection represent the core focus for GDPR readiness. Organizations must focus on adhering to principles, implementing processes to satisfy privacy rights of the individual, and securing data. Principles  Data processed lawfully, fairly, and transparently  Only collect personal data needed  Accuracy of personal data must be maintained  Minimize the time data is kept in a form to identify data subjects  Maintain the confidentiality and integrity of personal data Privacy (rights of data subjects)  Transparent information, communication and modalities for the exercise of the rights of the data subject  Information to be provided where personal data are collected from the data subject  Right of access by the data subject  Right to rectification  Right to erasure (‘right to be forgotten’)  Right to restriction of processing  Right to data portability Protection (controllers and processors)  Data Protection Officer (DPO)  Data protection by design  Records of processing activities  Security of processing  Notification of a personal data breach to the supervisory authority  Communication of a personal data breach to the data subject  Data protection impact assessment  Code of conduct
  • 4. GDPR EXECUTIVE OVERVIEW EXECUTION 4 GDPR requires the organization to address privacy and security of personal data. A proven approach to gaining clarity on GDPR relevance and understanding how to execute is described below. The Data Protection Officer (DPO) must lead the effort to achieve and maintain alignment. Preparation • Assign data privacy ownership • Understand the regulation Assessment • Understand the risk of activities • Perform Readiness Assessment Implementation • Inform the Organization • Address consent • Address rights of the individual • Protect personal data Maintenance • Operationalize GDPR controls
  • 5. GDPR EXECUTIVE OVERVIEW KEY CONSIDERATIONS 5 GDPR readiness can be complex for some organizations. Leadership should begin to prepare the organization for the journey. 1. Key is establishing the DPO role (internal or external) 2. Gain clarity on the organization’s responsibility 3. Complying with rights of the individual is not trivial – business processes, service desk, and technology impacts. Factor effort into 2018 budget – resource impact is key consideration (assuming good security practices). 4. Processor assessment is key – liability isn’t shifted to the processor 5. Certification is not defined and is not required. DPA (supervisory authority) will assign certification bodies and certification guidelines. Move forward with readiness while tracking DPA guidance.
  • 6. GDPR EXECUTIVE OVERVIEW GDPR MISPERCEPTIONS 6 Understanding GDPR requirements can be complex. There are several common misperceptions that should be clarified. 1. A Data Protection Officer is required for all organizations 2. Each GDPR incident will carry a fine equivalent to the greater of 20 mil Euro or 4% annual worldwide revenue 3. Consent is always required for processing of personal data 4. Parental consent is always required when collecting personal information from a child 5. Individuals have the absolute right to be forgotten 6. Biometric data is sensitive data 7. Controllers do not require processing agreements with processors – GDPR takes care of this

Editor's Notes

  • #3: “Personal data”* means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier: Name; Identification number; Location data; Online identifier (e.g., email address); Physical and/or physiological; Genetic; Economic; Cultural or ethnic
  • #4: Security of processing – anonymization and psuedonymization represent additional security requirements (potentially) Data processed lawfully: consent obtained, processing conducted in accordance with stated purpose, and complies with GDPR Code of conduct establishes readiness with GDPR. Communicates how the organization will comply and manage risk. 'cross-border processing' means either: (a) processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or (b) processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.
  • #5: The critical path is implementing business processes to address the rights of the individual – right to access personal data, right to correction, right to be forgotten, etc. Understanding data – what data do you have? Data governance – What data do I have? How is it used? Do I need it? How do I protect it. Be able to defend controls
  • #6: Joint Controllers and data ownership – how does this work Cross-border traffic – where does it apply and what are the implications Data subjects ability to withdraw consent – what’s the impact Certification w/ Supervisor Authority Anonymization of personal data – blurring/fuzzing of non-data subjects in video and other media Customers leaving the platform – how does this work and what are the implications Records of processing Activities (Article 30 (5)) - applicability to dscout. How to handle Privacy Policy separate from agreeing to TOS?
  • #7: Joint Controllers and data ownership – how does this work Cross-border traffic – where does it apply and what are the implications Data subjects ability to withdraw consent – what’s the impact Certification w/ Supervisor Authority Anonymization of personal data – blurring/fuzzing of non-data subjects in video and other media Customers leaving the platform – how does this work and what are the implications Records of processing Activities (Article 30 (5)) - applicability to dscout. How to handle Privacy Policy separate from agreeing to TOS?