SlideShare uma empresa Scribd logo
1 de 30
Baixar para ler offline
1
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Six Steps to GDPR
Readiness
Is Your Organization Ready for the
General Data Protection Regulation?
Jonathan Adams, Research Director
GDPR
2
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Peter Steiner; New Yorker Magazine; July 1993
3
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR3 Reasons to Care
4
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
1. Reduce Costs
Fines up to 4% of Global Revenue
*2016 Annual Revenues
5
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
2. Increase Margins
GDPR Capabilities support digital transformation goals and drive
new business models:
• Consumer
Centric PLM
• Supply Chain &
Channel
Optimization
• Customer 360
programs
6
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
3. Grow Revenue
Data Monetization &
New Revenue Streams
• Sports “Wearables”
• Self Identification at POI
• Cloud Based Services
“Trust” with Partners
& Customers
7
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
The Clock is Ticking…
8
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Defining GDPR
GDPR is a comprehensive set of privacy regulations designed to protect data for individuals
within the European Union.
Objective:
• Give individuals control of their personal data
• Regulatory consistency across the EU
Impact:
• Covers personal data collected in EU regardless of where the data
collector is located
• All US based multi nationals doing business with people in Europe
will be impacted
9
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR’s Impact on Companies
Any business (foreign or domestic) engaged with individuals within the EU
The notion of Personal Information (PI) is broadly defined: data that has the
potential to identify a person living in Europe falls under the GDPR
GDPR applies “horizontally” across the organization’s business components,
and “vertically” at all decision making levels.
GDPR applies across the complete value chain. Organizations are obligated to
verify the compliance of parties with which they do business.
10
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR Requires Interpretation
General Data
Protection Regulation
11
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR Requires Interpretation
It’s Comprehensive & Tightly Written
• All personal information regardless of where it came from and how it is used is governed
It’s Principle Based
• Requires companies to adopt privacy principles at the cultural level
It’s Compromise Legislation
• GDPR is a piece of what legal scholars call compromise legislation: a legislative text that tries to
satisfy two starkly opposed sides of the data protection debate
When Interpretation is Required, Best Practices are Critical
12
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
The Governance Challenge
Creating transparent &
defensible best practices
that address “principles”
13
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Risk
Management
Accountability
Org Design
Data Lineage
Process
Alignment
PII Cataloging International
Partner
Management
Metadata
Data
Governance
Data
Architecture
Data
Operations
Data Discovery
Best Practices
Security
Data
Management
Privacy
Cloud Services
IoT
The Governance Challenge
Mapping the best practices to observable & measurable
activities across many functional areas
Processes
Objectives
Standards
Metrics
Data
Rules
14
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
The 4 Core Capabilities
GDPR requirements can be simplified by
organizing around four core capability areas:
Consultation
& Reporting
• Certification
• Risk Management
• Organizational
Alignment
• Privacy by Design
• Risk Management
• Communication
• Remediation
• People
• Partners
• Regulators
• Organization
15
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
People: The “owners” of Personal Information
Forget
Quarantine
Package
Fix
Consent
Notification
Access
• Greater detail and clarity is
called for when collecting
data
• Consent must be explicit as
to use of data, how it will be
processed, and by whom
• Notification of breach is
required (within 72 hours to
the regulator)
Under GDPR Individuals
have the following rights:
• To be Informed
• To Access
• To Rectify
• To Erasure
• To Restrict Processing
• To Data Portability
• To Object
• Related to automated
Decision Making and
Profiling
Obligations Rights
16
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Organization: “Data Protection by Design”
Data
Management
International
Best Practices
Risk
Management
Accountability
Obligations
• Accountability – vertically, horizontally and
externally
• Data Protection Officer required for most
large companies
• Best practice “Codes of Conduct” mitigate
against enforcement action
• Assessment of risk will drive multiple
decisions – it needs to be transparent and
defensible
• Cross border data exchanges do not obviate
requirements
17
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Partners: A New Risk Dimension
Certification
Risk
Management
Processor
Compliance
Obligations
• Transfers of Personal Information between your
company and business partners does not transfer
the responsibility to ensure it is safeguarded – it is
still yours to look after
• Establish a way to ensure your partners are
providing GDPR level security
• Best practices certifications that support third
party audits will streamline assessment process
and mitigate risk
• Due diligence and transparency is key to
demonstrating diligence
18
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Regulators: Communication is key
Consultation
Best Practices
Obligations
• Notification is required in the event of a breach
• “Breach” is broadly defined: destruction, loss,
alteration, unauthorized disclosure of, or access
to, personal data
• Reporting to regulators within 72 hours when
breach is likely to result in a risk to the rights and
freedoms of individuals
• “Prior Consultation” is an expectation
• Privacy Impact Assessment anchors the regulator
and risk discussions
• Best Practices will streamline these discussions
19
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPR6 Steps to Readiness
20
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
1. Readiness Baseline
Compliance Capability Readiness=+
Do the Right Thing – Do it Right!
Understand Where You Are
21
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
2. Best Practices
Aligning to Recognized Best Practice Frameworks Mitigates Risk
2 Talk the Talk – Walk the Walk
3 Promote within Industry Associations
Pick a Framework That Works for You1
Understand How You Want to Manage
22
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
What is my GDPR Related Data?
23
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
3. Catalog
“To understand yourself is the beginning of wisdom.” – Krishnamaurti
2 Catalog Data: Foundational to Managing Data
3 Describe Data: Tag to Answer Compliance
Requirements
Identify Data: PI; Sensitive; Packaged; Erasable1
Understand What You are Managing
24
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Who is in charge? Why is this information valuable? And what is the impact of a privacy breach?
Why Do I Have It; How Is It Used?
25
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
4. Data Lifecycle
Where Is It and How Is It Used?
Lineage is a challenge!
• E-commerce sites
• Marketing functions
• Shipping fulfillment
• CRM
Start with known
Business
Functions
Focus on Core
Requirements
• Consent
• Notification
• Remediation
• Partner Management
26
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
5. Build Risk Capabilities
Defensible; Transparent; Demonstrable
Vulnerabilities
17-2
32-1
32-2
33-1
33-3
34-1
GDPR
Risk
Areas
34-3
35-1
35-7-c,d
35-11
49-1-a
Practices
Mitigation
RiskGovernance
Risk Analysis &
Metrics
“To [the] rights
and freedoms of
natural persons”
27
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Am I Ready For the Regulators?
28
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
6. Governance Framework
Operating
Model
Organizational
Alignment
Mobilizing Cross-
Functional Teams
Empowerment
(with Rules and
Tools)
Outcome focused
Metrics
Ownership &
Accountability
Step-Change
Change Management
Pulling it all Together!
29
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
GDPRQuestions?
Jonathan Adams; 443-223-2534
jonathan.adams@datumstrategy.com
30
Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC
Some Useful Links
Whitepapers
• GDPR Guide: 3 Steps to Readiness: http://info.datumstrategy.com/gdpr-guide-ebook-paper-privacy-compliance
Blogs
• Will the Privacy Shield Protect You? http://www.datumstrategy.com/blog/will-the-privacy-shield-protect-you
• 7 Key GDPR Requirements & the Role of Data Governance: http://www.datumstrategy.com/blog/gdpr-requirements-and-data-
governance
• What’s GDPR and the Penalty for Not Complying? http://www.datumstrategy.com/blog/what-is-gdpr-fines-penalties-for-not-
complying
Websites
• GDPR Portal: http://www.eugdpr.org
• DATUM Strategy: http://www.datumstrategy.com
Informative Sites:
• The UK Information Commissioner’s Office (ICO) has a well put together site that makes it easy to find answers:
https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/
• The Linklaters Law Firm has a number of resource papers (versus marketing papers): The General Data Protection Regulation:
A Survival Guide; and A report on global data protection laws in 2016.
https://clientsites.linklaters.com/Clients/dataprotected/Pages/TheGDPR.aspx
• The book by Chiara Rustici: Applying the GDPR: Privacy Rules For The Data Economy is very informative. Pre-release is out
http://shop.oreilly.com/product/0636920055723.do

Mais conteúdo relacionado

Mais procurados

Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideZymplify
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceIDERA Software
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role HackerOne
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR ComplianceDATAVERSITY
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationIBM Security
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data GovernanceDATUM LLC
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...DATUM LLC
 

Mais procurados (20)

Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
Ardoq in Edinburgh - Events - Building Resilience in a Post-GDPR World (14-au...
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity Legislation
 
7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance7 Key GDPR Requirements & the Role of Data Governance
7 Key GDPR Requirements & the Role of Data Governance
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
Data Discovery & Search: Making it an Integral Part of Analytics, Compliance ...
 

Semelhante a Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regulations

Enterprise Data World 2018
Enterprise Data World 2018Enterprise Data World 2018
Enterprise Data World 2018jadams6
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Software Integrity Group
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?Gareth Miller
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides DATUM LLC
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionInfoGoTo
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Complianceaccenture
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessOlivier BARROT
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataNeo4j
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017Match-Maker Ventures
 
Symantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR ComplianceSymantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR ComplianceSymantec
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the Newaccenture
 
3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.Richard Kranendonk
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 

Semelhante a Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regulations (20)

Enterprise Data World 2018
Enterprise Data World 2018Enterprise Data World 2018
Enterprise Data World 2018
 
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
Synopsys Security Event Israel Presentation: Taking Your Software to the GDPR...
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?
 
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM WorksGDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
 
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
 
Bridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and RetentionBridging the Gap Between Privacy and Retention
Bridging the Gap Between Privacy and Retention
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
GDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your businessGDPR what you should know and how to minimize impact on your business
GDPR what you should know and how to minimize impact on your business
 
How to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected DataHow to turn GDPR into a Strategic Advantage using Connected Data
How to turn GDPR into a Strategic Advantage using Connected Data
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
Symantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR ComplianceSymantec Webinar Part 2 of 6 GDPR Compliance
Symantec Webinar Part 2 of 6 GDPR Compliance
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
 
3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.3 minute reading time on how you can comply with GDPR.
3 minute reading time on how you can comply with GDPR.
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
13687562.ppt
13687562.ppt13687562.ppt
13687562.ppt
 

Mais de DATUM LLC

The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?DATUM LLC
 
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...DATUM LLC
 
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...DATUM LLC
 
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...DATUM LLC
 
Business KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for HersheyBusiness KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for HersheyDATUM LLC
 
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics 5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics DATUM LLC
 
Data Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk DownData Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk DownDATUM LLC
 
5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital Transformation5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital TransformationDATUM LLC
 
5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANA5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANADATUM LLC
 
14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy Statistics14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy StatisticsDATUM LLC
 
3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...DATUM LLC
 
How JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANAHow JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANADATUM LLC
 
9 Funny Data "Fails"
9 Funny Data "Fails" 9 Funny Data "Fails"
9 Funny Data "Fails" DATUM LLC
 
How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model DATUM LLC
 

Mais de DATUM LLC (14)

The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?
 
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
DGIQ 2018 Presentation: How to be successful in the post GDPR landscape – bui...
 
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...DGIQ 2018 Presentation:  A Lawyer, a Salesperson and the Operations Guy Walk ...
DGIQ 2018 Presentation: A Lawyer, a Salesperson and the Operations Guy Walk ...
 
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
GDPR Audit Resilience: How to Align Diverse Internal Stakeholder Needs and De...
 
Business KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for HersheyBusiness KPIs & Data Governance: A Sweet Combination for Hershey
Business KPIs & Data Governance: A Sweet Combination for Hershey
 
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics 5 Steps to Prepare for Digital Transformation & Real-Time Analytics
5 Steps to Prepare for Digital Transformation & Real-Time Analytics
 
Data Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk DownData Leadership Lessons From Black Hawk Down
Data Leadership Lessons From Black Hawk Down
 
5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital Transformation5 Steps to Prepare for Digital Transformation
5 Steps to Prepare for Digital Transformation
 
5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANA5 Steps to Prepare for SAP S4HANA
5 Steps to Prepare for SAP S4HANA
 
14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy Statistics14 Shocking Digital Transformation & Digital Economy Statistics
14 Shocking Digital Transformation & Digital Economy Statistics
 
3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...3 Essential Steps to Deliver Information Governance Success Through Strategy ...
3 Essential Steps to Deliver Information Governance Success Through Strategy ...
 
How JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANAHow JCI Prepared a Data Governance Program for Big Data & MDG on HANA
How JCI Prepared a Data Governance Program for Big Data & MDG on HANA
 
9 Funny Data "Fails"
9 Funny Data "Fails" 9 Funny Data "Fails"
9 Funny Data "Fails"
 
How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model How to Build & Sustain a Data Governance Operating Model
How to Build & Sustain a Data Governance Operating Model
 

Último

Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...HyderabadDolls
 
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...ZurliaSoop
 
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptxRESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptxronsairoathenadugay
 
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With OrangePredicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With OrangeThinkInnovation
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样wsppdmt
 
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...Bertram Ludäscher
 
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...gajnagarg
 
Statistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numbersStatistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numberssuginr1
 
7. Epi of Chronic respiratory diseases.ppt
7. Epi of Chronic respiratory diseases.ppt7. Epi of Chronic respiratory diseases.ppt
7. Epi of Chronic respiratory diseases.pptibrahimabdi22
 
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Valters Lauzums
 
Gartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptxGartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptxchadhar227
 
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24  Building Real-Time Pipelines With FLaNKDATA SUMMIT 24  Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNKTimothy Spann
 
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...HyderabadDolls
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...gajnagarg
 
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...Health
 
TrafficWave Generator Will Instantly drive targeted and engaging traffic back...
TrafficWave Generator Will Instantly drive targeted and engaging traffic back...TrafficWave Generator Will Instantly drive targeted and engaging traffic back...
TrafficWave Generator Will Instantly drive targeted and engaging traffic back...SOFTTECHHUB
 
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...gajnagarg
 
Computer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdfComputer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdfSayantanBiswas37
 
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...HyderabadDolls
 
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...gragchanchal546
 

Último (20)

Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
Sonagachi * best call girls in Kolkata | ₹,9500 Pay Cash 8005736733 Free Home...
 
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Surabaya ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
 
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptxRESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
 
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With OrangePredicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
 
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...Reconciling Conflicting Data Curation Actions:  Transparency Through Argument...
Reconciling Conflicting Data Curation Actions: Transparency Through Argument...
 
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Latur [ 7014168258 ] Call Me For Genuine Models We ...
 
Statistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numbersStatistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numbers
 
7. Epi of Chronic respiratory diseases.ppt
7. Epi of Chronic respiratory diseases.ppt7. Epi of Chronic respiratory diseases.ppt
7. Epi of Chronic respiratory diseases.ppt
 
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
 
Gartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptxGartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptx
 
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24  Building Real-Time Pipelines With FLaNKDATA SUMMIT 24  Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
 
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
Gomti Nagar & best call girls in Lucknow | 9548273370 Independent Escorts & D...
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
 
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
 
TrafficWave Generator Will Instantly drive targeted and engaging traffic back...
TrafficWave Generator Will Instantly drive targeted and engaging traffic back...TrafficWave Generator Will Instantly drive targeted and engaging traffic back...
TrafficWave Generator Will Instantly drive targeted and engaging traffic back...
 
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Indore [ 7014168258 ] Call Me For Genuine Models We...
 
Computer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdfComputer science Sql cheat sheet.pdf.pdf
Computer science Sql cheat sheet.pdf.pdf
 
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
 
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
Gulbai Tekra * Cheap Call Girls In Ahmedabad Phone No 8005736733 Elite Escort...
 

Six Steps to Addressing Data Governance under GDPR and US Privacy Shield Regulations

  • 1. 1 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Six Steps to GDPR Readiness Is Your Organization Ready for the General Data Protection Regulation? Jonathan Adams, Research Director GDPR
  • 2. 2 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Peter Steiner; New Yorker Magazine; July 1993
  • 3. 3 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR3 Reasons to Care
  • 4. 4 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 1. Reduce Costs Fines up to 4% of Global Revenue *2016 Annual Revenues
  • 5. 5 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 2. Increase Margins GDPR Capabilities support digital transformation goals and drive new business models: • Consumer Centric PLM • Supply Chain & Channel Optimization • Customer 360 programs
  • 6. 6 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 3. Grow Revenue Data Monetization & New Revenue Streams • Sports “Wearables” • Self Identification at POI • Cloud Based Services “Trust” with Partners & Customers
  • 7. 7 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC The Clock is Ticking…
  • 8. 8 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Defining GDPR GDPR is a comprehensive set of privacy regulations designed to protect data for individuals within the European Union. Objective: • Give individuals control of their personal data • Regulatory consistency across the EU Impact: • Covers personal data collected in EU regardless of where the data collector is located • All US based multi nationals doing business with people in Europe will be impacted
  • 9. 9 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR’s Impact on Companies Any business (foreign or domestic) engaged with individuals within the EU The notion of Personal Information (PI) is broadly defined: data that has the potential to identify a person living in Europe falls under the GDPR GDPR applies “horizontally” across the organization’s business components, and “vertically” at all decision making levels. GDPR applies across the complete value chain. Organizations are obligated to verify the compliance of parties with which they do business.
  • 10. 10 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR Requires Interpretation General Data Protection Regulation
  • 11. 11 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR Requires Interpretation It’s Comprehensive & Tightly Written • All personal information regardless of where it came from and how it is used is governed It’s Principle Based • Requires companies to adopt privacy principles at the cultural level It’s Compromise Legislation • GDPR is a piece of what legal scholars call compromise legislation: a legislative text that tries to satisfy two starkly opposed sides of the data protection debate When Interpretation is Required, Best Practices are Critical
  • 12. 12 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC The Governance Challenge Creating transparent & defensible best practices that address “principles”
  • 13. 13 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Risk Management Accountability Org Design Data Lineage Process Alignment PII Cataloging International Partner Management Metadata Data Governance Data Architecture Data Operations Data Discovery Best Practices Security Data Management Privacy Cloud Services IoT The Governance Challenge Mapping the best practices to observable & measurable activities across many functional areas Processes Objectives Standards Metrics Data Rules
  • 14. 14 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC The 4 Core Capabilities GDPR requirements can be simplified by organizing around four core capability areas: Consultation & Reporting • Certification • Risk Management • Organizational Alignment • Privacy by Design • Risk Management • Communication • Remediation • People • Partners • Regulators • Organization
  • 15. 15 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC People: The “owners” of Personal Information Forget Quarantine Package Fix Consent Notification Access • Greater detail and clarity is called for when collecting data • Consent must be explicit as to use of data, how it will be processed, and by whom • Notification of breach is required (within 72 hours to the regulator) Under GDPR Individuals have the following rights: • To be Informed • To Access • To Rectify • To Erasure • To Restrict Processing • To Data Portability • To Object • Related to automated Decision Making and Profiling Obligations Rights
  • 16. 16 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Organization: “Data Protection by Design” Data Management International Best Practices Risk Management Accountability Obligations • Accountability – vertically, horizontally and externally • Data Protection Officer required for most large companies • Best practice “Codes of Conduct” mitigate against enforcement action • Assessment of risk will drive multiple decisions – it needs to be transparent and defensible • Cross border data exchanges do not obviate requirements
  • 17. 17 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Partners: A New Risk Dimension Certification Risk Management Processor Compliance Obligations • Transfers of Personal Information between your company and business partners does not transfer the responsibility to ensure it is safeguarded – it is still yours to look after • Establish a way to ensure your partners are providing GDPR level security • Best practices certifications that support third party audits will streamline assessment process and mitigate risk • Due diligence and transparency is key to demonstrating diligence
  • 18. 18 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Regulators: Communication is key Consultation Best Practices Obligations • Notification is required in the event of a breach • “Breach” is broadly defined: destruction, loss, alteration, unauthorized disclosure of, or access to, personal data • Reporting to regulators within 72 hours when breach is likely to result in a risk to the rights and freedoms of individuals • “Prior Consultation” is an expectation • Privacy Impact Assessment anchors the regulator and risk discussions • Best Practices will streamline these discussions
  • 19. 19 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPR6 Steps to Readiness
  • 20. 20 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 1. Readiness Baseline Compliance Capability Readiness=+ Do the Right Thing – Do it Right! Understand Where You Are
  • 21. 21 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 2. Best Practices Aligning to Recognized Best Practice Frameworks Mitigates Risk 2 Talk the Talk – Walk the Walk 3 Promote within Industry Associations Pick a Framework That Works for You1 Understand How You Want to Manage
  • 22. 22 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC What is my GDPR Related Data?
  • 23. 23 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 3. Catalog “To understand yourself is the beginning of wisdom.” – Krishnamaurti 2 Catalog Data: Foundational to Managing Data 3 Describe Data: Tag to Answer Compliance Requirements Identify Data: PI; Sensitive; Packaged; Erasable1 Understand What You are Managing
  • 24. 24 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Who is in charge? Why is this information valuable? And what is the impact of a privacy breach? Why Do I Have It; How Is It Used?
  • 25. 25 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 4. Data Lifecycle Where Is It and How Is It Used? Lineage is a challenge! • E-commerce sites • Marketing functions • Shipping fulfillment • CRM Start with known Business Functions Focus on Core Requirements • Consent • Notification • Remediation • Partner Management
  • 26. 26 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 5. Build Risk Capabilities Defensible; Transparent; Demonstrable Vulnerabilities 17-2 32-1 32-2 33-1 33-3 34-1 GDPR Risk Areas 34-3 35-1 35-7-c,d 35-11 49-1-a Practices Mitigation RiskGovernance Risk Analysis & Metrics “To [the] rights and freedoms of natural persons”
  • 27. 27 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Am I Ready For the Regulators?
  • 28. 28 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC 6. Governance Framework Operating Model Organizational Alignment Mobilizing Cross- Functional Teams Empowerment (with Rules and Tools) Outcome focused Metrics Ownership & Accountability Step-Change Change Management Pulling it all Together!
  • 29. 29 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC GDPRQuestions? Jonathan Adams; 443-223-2534 jonathan.adams@datumstrategy.com
  • 30. 30 Confidential and Proprietary. All rights reserved Copyright© 2017. DATUM LLC Some Useful Links Whitepapers • GDPR Guide: 3 Steps to Readiness: http://info.datumstrategy.com/gdpr-guide-ebook-paper-privacy-compliance Blogs • Will the Privacy Shield Protect You? http://www.datumstrategy.com/blog/will-the-privacy-shield-protect-you • 7 Key GDPR Requirements & the Role of Data Governance: http://www.datumstrategy.com/blog/gdpr-requirements-and-data- governance • What’s GDPR and the Penalty for Not Complying? http://www.datumstrategy.com/blog/what-is-gdpr-fines-penalties-for-not- complying Websites • GDPR Portal: http://www.eugdpr.org • DATUM Strategy: http://www.datumstrategy.com Informative Sites: • The UK Information Commissioner’s Office (ICO) has a well put together site that makes it easy to find answers: https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/accountability-and-governance/ • The Linklaters Law Firm has a number of resource papers (versus marketing papers): The General Data Protection Regulation: A Survival Guide; and A report on global data protection laws in 2016. https://clientsites.linklaters.com/Clients/dataprotected/Pages/TheGDPR.aspx • The book by Chiara Rustici: Applying the GDPR: Privacy Rules For The Data Economy is very informative. Pre-release is out http://shop.oreilly.com/product/0636920055723.do