SlideShare uma empresa Scribd logo
1 de 10
EXPLORING THE IMPACT ON ORGANISATIONS & FINANCIAL INSTITUTIONS
GENERAL DATA PROTECTION REGULATION (GDPR)
 The GDPR protects natural persons with regard to the processing of personal data &
gives citizens more control over their personal data.
 GDPR applies to all companies processing & holding personal data of data subjects
residing in the EU, regardless of the company’s location.
 Organizations must keep record of and monitor personal data processing activities.
 As data controller, organizations must keep record of & monitor personal data
processing activities. This includes personal data handled within the organization, but
also by third parties - so called data processors.
 Data processors can be anything from Software-as-a-Service providers to embedded
third party services, tracking and profiling visitors on the organization’s website.
 Organizations with more than 250 employees and or companies processing sensitive
personal data at a large scale to employ or train a data protection officer (DPO).
 The fines for violating the GDPR norms can be significant and the maximum penalty is
4% of annual turnover or €20 million which ever is higher.
 In relation to Brexit, the UK Government plans to implement equivalent legislation
that will largely follow the GDPR.
GENERAL DATA PROTECTION REGULATION (GDPR)
NATURAL
PERSONS
DATA
CONTROLLERS
GDPR
DATA
PROCESSORS
GDPR
PENALITY
TERRITORIAL
SCOPE
RETRACEABILITY
DATA SUBJECT
RIGHTS
DATA BREACH
PRIVACY
AGREEMENT
DATA
INVENTORY
DATA
PROTECTION
OFFICER
GDPR DESCRIPTOR’S
 NATURAL PERSON
 PROTECTION OF PRIVACY
 CROSS-FRONTIER DATA FLOW
 DATA-PROCESSING LAW
 ACCESS TO INFORMATION
 DATA PROTECTION
 DISCLOSURE OF INFORMATION
 PERSONAL DATA
 FREEDOM, SECURITY & JUSTICE
GENERAL DATA PROTECTION REGULATION (GDPR)
System
Analysis
GAP
Identification
System
Transformation
Data Inventory
Management
Privacy
Design
Third Party
Requirements
GDPR
Compliant
GDPR ACTION PLAN
• Study Business Insight
• Organisation and Accountability
• Develop Strategy & Roadmap
• Data Breach Handling Procedure
• Data Subject Rights procedure
• Data Protection Officer
• Data Processing Agreements
• Privacy Risk Assessment
• Risk mitigation
• Risk Acceptance
• Employee training and awareness
• Third Party Agreements
GENERAL DATA PROTECTION REGULATION (GDPR)
RIGHT OF DATA SUBJECT
 Breach Notification – GDPR compliant organizations must notify end users of any data
breaches within 72 hours of first coming aware of the situation.
 Right to Access – Compliant companies must provide the personal information stored about
each end user and information regarding how the data is being used and where it is stored
on request by the data subject.
 Right to be Forgotten: This requirement entitles a data subject to have his/her personal data
erased and have it no longer disseminated to third parties or exposed to third party
processing.
 Data Portability – This rule requires GDPR compliant companies to provide end user data in a
commonly used and machine readable format” on-demand allowing users to take their data
to another data user.
 Privacy by Design – Privacy by Design requires the inclusion of data protection at the onset
of system design versus being added later.
 Data Protection Officers – DPOs are mandatory for those companies whose core activities
include systematic monitoring of customer data on a large scale or hosting data relating to
criminal convictions and offenses.
GENERAL DATA PROTECTION REGULATION (GDPR)
BREACH NOTIFICATION
RIGHT TO ACCESS
RIGHT TO BE FORGOTTEN
DATA PROTABILITY
PRIVACY BY DESIGN
DATA PROTECTION OFFICER
RIGHT OF DATA SUBJECT
 The controller shall take appropriate measures to provide any information to the
data subject in a concise, transparent, intelligible and easily accessible form, using
clear and plain language. (Article 12).
 The controller to provide the data subject with the purpose for which the data are
collected & time period for which the data shall be stored. (Article 13).
 Data subjects will have the right to obtain a copy of the personal data you hold
about them & to an in-depth description of how it is being processed (Article 15).
 They have the right to have inaccurate personal data corrected (Article 16).
 They have the right to have inaccurate personal data or their data deleted (Article
17).
 The data subject shall have the right restrict the controller from processing their
personal data, except for exercise or defense of legal claims or for the protection
of the rights of another natural or legal person or for reasons of important public
interest of the Union or of a Member State ( Article 18).
GENERAL DATA PROTECTION REGULATION (GDPR)
CHAPTER III - Rights of
the data subject - Article
12 to 22 & 34
CHAPTER VIII - Remedies,
liability and penalties -
Article 77, 78, 79 & 82
RULES FOR BUSINESSES
 Single set of EU-wide rules
 Data protection officer
 EU rules for non-EU companies
 Data protection by design and by default
 Data protection safeguards
 Pseudonymisation & Encryption
 Data protection impact assessment
 Conditions for Data Subject consent
 Data Breach Notification to Data Subject
 Data breach Notification to the supervisory authority
 Acting as Representatives of controllers
 Record-keeping of processing activities
 Exemptions - Processing of data
 Penalty for non-compliance
GENERAL DATA PROTECTION REGULATION (GDPR)
RIGHTS OF DATA
SUBJECT
DATA
INVENTORY
EU & NON EU
ORGANISATIONS
SUPERVISORY
AUTHORITY
GDPR
GENERAL DATA PROTECTION REGULATION AND FINANCIAL SECTOR
 The financial sector is one of the more highly regulated sector worldwide, but
many Banks & Credit Institutions have nonetheless been caught off guard by the
complexity of the new EU General Data Protection Regulation (GDPR).
 Organizations risk regulator fines, litigation costs & contract opportunities. The
biggest risk is likely to be in the events of outsourcing of work to third parties,
Organizations within EU as well as Organizations who deal with EU citizens
personal data have to check their third party contracts are GDPR compliant.
 They should also demonstrate to the regulator that:
I. They know where your data resides,
II. Have breach handling process is in place,
III. They respond to the rights of the individual
 This Regulation, takes effect on 25 May 2018, revamps the way organizations knob
personal data. It includes countless requirements, which Banks & Financial
Institutions should take as soon as possible, comply with the requirements of
GDPR.
GENERAL DATA PROTECTION REGULATION (GDPR)
GDPR
PERSONAL DATA DATA PROTECTION COMPLIANCE
FINANCIAL
INSTITUTIONS
ROLE OF DATA PROTECTION OFFICER (DPO)
 A data protection officer may be a staff member of the controller or processor, or
fulfil the tasks on the basis of a service contract.
 Be the point of contact for data subjects and for cooperating and consulting with
national supervisory authorities, such as the Information Commissioner’s Office.
 Be consulted and provide advice during Data Protection Impact Assessments
 Ensure all future developments and system implementations incorporated fulfill the
principles of data.
 Assist in creating a platform and environment capable of continuously
demonstrating control of personal data
 Have contingency plan (including containment, rectification and communications),
to safe guard data and process to inform data subjects, if something go wrong.
 A data protection officer shall be bound by secrecy or confidentiality concerning the
performance of his or her tasks, in accordance with Union or Member State law.
 A data protection officer shall directly report to the highest management level.
GENERAL DATA PROTECTION REGULATION (GDPR)
DATA INVENTORY
DATA PROTECTION
OFFICER
THANK YOU

Mais conteúdo relacionado

Mais procurados

Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hrTushar Rajput
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill Komal Gadia
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_indiaAltacit Global
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
Data protection ppt
Data protection pptData protection ppt
Data protection pptgrahamwell
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) Kimberly Simon MBA
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance PreparationLawPlus Ltd.
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018amirhannan
 

Mais procurados (20)

GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hr
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_india
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Data protection
Data protectionData protection
Data protection
 
PDPA Compliance Preparation
PDPA Compliance PreparationPDPA Compliance Preparation
PDPA Compliance Preparation
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR
GDPRGDPR
GDPR
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018
 
DPDP Act 2023.pdf
DPDP Act 2023.pdfDPDP Act 2023.pdf
DPDP Act 2023.pdf
 

Semelhante a GDPR

My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRzayadeen2003
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanEquiGov Institute
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analyticsbrunomase
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. dan hyde
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
How does GDPR Regulation help in Data Protection and Data Privacy?
How does GDPR Regulation help in Data Protection and Data Privacy?How does GDPR Regulation help in Data Protection and Data Privacy?
How does GDPR Regulation help in Data Protection and Data Privacy?TobyRobinson13
 
GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant? GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant? GreenRope
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingPromptCloud
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowSymantec
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationN N
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018Dean Evans
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 

Semelhante a GDPR (20)

My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analytics
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
How does GDPR Regulation help in Data Protection and Data Privacy?
How does GDPR Regulation help in Data Protection and Data Privacy?How does GDPR Regulation help in Data Protection and Data Privacy?
How does GDPR Regulation help in Data Protection and Data Privacy?
 
GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant? GDPR: Are you EU Compliant?
GDPR: Are you EU Compliant?
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and Processing
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t know
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
Satori GDPR Overview 2018
Satori GDPR Overview 2018Satori GDPR Overview 2018
Satori GDPR Overview 2018
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 

Último

Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaShree Krishna Exports
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfOnline Income Engine
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...noida100girls
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insightsseri bangash
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdftbatkhuu1
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetDenis Gagné
 

Último (20)

Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in India
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
Unlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdfUnlocking the Secrets of Affiliate Marketing.pdf
Unlocking the Secrets of Affiliate Marketing.pdf
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insights
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdf
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
 

GDPR

  • 1. EXPLORING THE IMPACT ON ORGANISATIONS & FINANCIAL INSTITUTIONS GENERAL DATA PROTECTION REGULATION (GDPR)
  • 2.  The GDPR protects natural persons with regard to the processing of personal data & gives citizens more control over their personal data.  GDPR applies to all companies processing & holding personal data of data subjects residing in the EU, regardless of the company’s location.  Organizations must keep record of and monitor personal data processing activities.  As data controller, organizations must keep record of & monitor personal data processing activities. This includes personal data handled within the organization, but also by third parties - so called data processors.  Data processors can be anything from Software-as-a-Service providers to embedded third party services, tracking and profiling visitors on the organization’s website.  Organizations with more than 250 employees and or companies processing sensitive personal data at a large scale to employ or train a data protection officer (DPO).  The fines for violating the GDPR norms can be significant and the maximum penalty is 4% of annual turnover or €20 million which ever is higher.  In relation to Brexit, the UK Government plans to implement equivalent legislation that will largely follow the GDPR. GENERAL DATA PROTECTION REGULATION (GDPR) NATURAL PERSONS DATA CONTROLLERS GDPR DATA PROCESSORS
  • 3. GDPR PENALITY TERRITORIAL SCOPE RETRACEABILITY DATA SUBJECT RIGHTS DATA BREACH PRIVACY AGREEMENT DATA INVENTORY DATA PROTECTION OFFICER GDPR DESCRIPTOR’S  NATURAL PERSON  PROTECTION OF PRIVACY  CROSS-FRONTIER DATA FLOW  DATA-PROCESSING LAW  ACCESS TO INFORMATION  DATA PROTECTION  DISCLOSURE OF INFORMATION  PERSONAL DATA  FREEDOM, SECURITY & JUSTICE GENERAL DATA PROTECTION REGULATION (GDPR)
  • 4. System Analysis GAP Identification System Transformation Data Inventory Management Privacy Design Third Party Requirements GDPR Compliant GDPR ACTION PLAN • Study Business Insight • Organisation and Accountability • Develop Strategy & Roadmap • Data Breach Handling Procedure • Data Subject Rights procedure • Data Protection Officer • Data Processing Agreements • Privacy Risk Assessment • Risk mitigation • Risk Acceptance • Employee training and awareness • Third Party Agreements GENERAL DATA PROTECTION REGULATION (GDPR)
  • 5. RIGHT OF DATA SUBJECT  Breach Notification – GDPR compliant organizations must notify end users of any data breaches within 72 hours of first coming aware of the situation.  Right to Access – Compliant companies must provide the personal information stored about each end user and information regarding how the data is being used and where it is stored on request by the data subject.  Right to be Forgotten: This requirement entitles a data subject to have his/her personal data erased and have it no longer disseminated to third parties or exposed to third party processing.  Data Portability – This rule requires GDPR compliant companies to provide end user data in a commonly used and machine readable format” on-demand allowing users to take their data to another data user.  Privacy by Design – Privacy by Design requires the inclusion of data protection at the onset of system design versus being added later.  Data Protection Officers – DPOs are mandatory for those companies whose core activities include systematic monitoring of customer data on a large scale or hosting data relating to criminal convictions and offenses. GENERAL DATA PROTECTION REGULATION (GDPR) BREACH NOTIFICATION RIGHT TO ACCESS RIGHT TO BE FORGOTTEN DATA PROTABILITY PRIVACY BY DESIGN DATA PROTECTION OFFICER
  • 6. RIGHT OF DATA SUBJECT  The controller shall take appropriate measures to provide any information to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language. (Article 12).  The controller to provide the data subject with the purpose for which the data are collected & time period for which the data shall be stored. (Article 13).  Data subjects will have the right to obtain a copy of the personal data you hold about them & to an in-depth description of how it is being processed (Article 15).  They have the right to have inaccurate personal data corrected (Article 16).  They have the right to have inaccurate personal data or their data deleted (Article 17).  The data subject shall have the right restrict the controller from processing their personal data, except for exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State ( Article 18). GENERAL DATA PROTECTION REGULATION (GDPR) CHAPTER III - Rights of the data subject - Article 12 to 22 & 34 CHAPTER VIII - Remedies, liability and penalties - Article 77, 78, 79 & 82
  • 7. RULES FOR BUSINESSES  Single set of EU-wide rules  Data protection officer  EU rules for non-EU companies  Data protection by design and by default  Data protection safeguards  Pseudonymisation & Encryption  Data protection impact assessment  Conditions for Data Subject consent  Data Breach Notification to Data Subject  Data breach Notification to the supervisory authority  Acting as Representatives of controllers  Record-keeping of processing activities  Exemptions - Processing of data  Penalty for non-compliance GENERAL DATA PROTECTION REGULATION (GDPR) RIGHTS OF DATA SUBJECT DATA INVENTORY EU & NON EU ORGANISATIONS SUPERVISORY AUTHORITY GDPR
  • 8. GENERAL DATA PROTECTION REGULATION AND FINANCIAL SECTOR  The financial sector is one of the more highly regulated sector worldwide, but many Banks & Credit Institutions have nonetheless been caught off guard by the complexity of the new EU General Data Protection Regulation (GDPR).  Organizations risk regulator fines, litigation costs & contract opportunities. The biggest risk is likely to be in the events of outsourcing of work to third parties, Organizations within EU as well as Organizations who deal with EU citizens personal data have to check their third party contracts are GDPR compliant.  They should also demonstrate to the regulator that: I. They know where your data resides, II. Have breach handling process is in place, III. They respond to the rights of the individual  This Regulation, takes effect on 25 May 2018, revamps the way organizations knob personal data. It includes countless requirements, which Banks & Financial Institutions should take as soon as possible, comply with the requirements of GDPR. GENERAL DATA PROTECTION REGULATION (GDPR) GDPR PERSONAL DATA DATA PROTECTION COMPLIANCE FINANCIAL INSTITUTIONS
  • 9. ROLE OF DATA PROTECTION OFFICER (DPO)  A data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.  Be the point of contact for data subjects and for cooperating and consulting with national supervisory authorities, such as the Information Commissioner’s Office.  Be consulted and provide advice during Data Protection Impact Assessments  Ensure all future developments and system implementations incorporated fulfill the principles of data.  Assist in creating a platform and environment capable of continuously demonstrating control of personal data  Have contingency plan (including containment, rectification and communications), to safe guard data and process to inform data subjects, if something go wrong.  A data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.  A data protection officer shall directly report to the highest management level. GENERAL DATA PROTECTION REGULATION (GDPR) DATA INVENTORY DATA PROTECTION OFFICER