SlideShare uma empresa Scribd logo
1 de 26
HOW TO GET
STARTED WITH BEING
GDPR COMPLIANT
BY SIDDHARTH RAM DINESH
Where do I begin
finding out about
GDPR?
What is GDPR?
How would a
company go about
being GDPR
compliant?
Why is GDPR
important?
Who does GDPR
affect ?
GDPR … What is it ?
“ The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a
regulation by which the European Parliament, the Council of the European Union
and the European Commission intend to strengthen and unify data protection for
all individuals within the European Union (EU). “
WHATS CHANGED?
One Set of Rules Across the EU
Personal Data Redefined
New Individual Rights
Mandatory Breach Notification
Financial Repercussions
Joint Responsibility
Information Governance
Truly Global Impact
GDPR - PROCESS FLOW
A generic process flow an
organization could follow to
achieve GDPR compliance before
May 25, 2018
Q2 2017 Q3 2017 Q4 2017 Q1 2018 Q2 2018
April May June July August September October November December January February March April May June
Awareness and Communication
Initiation Define policies and procedures
Regulation
date 25th May
2018
Current state
assessment and plan
Implement technology and business changes
Gap and Risk Assessment Training
Update Contracts
Update privacy notices and consent
GDPR PRocEss Flow TIMELINE
GAP ANALYSIS
MARKETING PROCUREMENT HRSUPPORTLEGAL IT
RAISE
AWARENESS
INFORMATION
HELD
CONCENT
INDIVIDUAL
RIGHTS
COMMUNICATING
PRIVACY
CHILDREN'S
DATA
DATA
PROTECTION
OFFICERS
DATA BREACHES INTERNATIONAL
LOCATIONS
Company Horizontals
Factors to check
ENTERPRISE RISK MANAGEMENT
“The GDPR does not define the notion of “risk”, but the recitals and the
substantive provisions include indications of the types of risks and harms to
individuals to be considered.“
Some of the possible risks are:
- Discrimination
- Identity theft / fraud, financial loss
- Reputation damage
- Loss of confidentiality of personal data protected by professional secrecy
- Processing large amounts of data affecting large numbers of individuals
INTERNAL COMMUNICATION
EdUCATE EMPLOYEES oN GDPR
● Make sure that decision makers and key people in your organisation are
aware that the law is changing to the GDPR.
● They are likely to identify areas that could cause compliance problems
under the GDPR.
OPERATIONAL POLICIES
UPDATE OPERATIONAL pOLICIES
Appoint a contact point for the data protection authority (DPA) and data
subjects, and a data protection officer (DPO) to ensure processing
operations are compliant.
Update company operational policies to be GDPR compliant
Create policies and rollout policies is a way that it’s as less disruptive as
possible
CHANGE MANAGEMENT
CHANGE MANAGEMENT AND
COMMUNICATION
Create a change management plan to incorporate and roll out all the required
policy changes throughout the company
Rollout change in policy to the customers updating them on the changes in
regulations and privacy policy
Update contracts with subcontractors and make sure they follow GDPR
guidelines
COMPLIANCE TESTING
Fulfill compliance before May 2018
Be compliant as soon as possible to avoid last minute changes.
Makes the organization’s functioning smooth and panic free.
Buffer time would allow the company to perfect the systems and avoid errors
after May 2018.
Hypothesis: The questions are asked by a large hospital chain that is validating its GDPR compliance
status.
Questions 1 and 2 based on Consent
1. Is the data subject aware of the personal data we possess?
a. Does the data we hold currently, post consent from the data subject?
b. Are we using the personal data for any other purpose other than what we got consent for?
c. Do we have a system/policy in place to handle consent (communicate, withdraw, update etc)
2. Do we have a system to process children's’ data?
a. Is the data of children below the age of 16 being held post consent from their parents?
b. Is the data used only for the purpose stated in the consent document?
Questions companies should ask
Questions 3 and 4 based on Data handling
3. Do we have a process to monitor where the data is being transferred?
a. Is the data transferred to any 3rd party companies like insurance or banks? If so is only the relevant data
transferred to them.
b. Is the 3rd party company that we are dealing with GDPR compliant?
c. Do we have a system in place to check and validate the compliance of the 3rd party companies
d. Is the data sent to any 3rd party applications being monitored and validated?
4. If the data that we have is being processed for any other reason other than stated in the consent
document, do we have a system to communicate that to the data subject?
a. Validate if the information is held for any reasons mentioned in the GDPR document which exempts the
need for consent
Questions companies should ask
Questions 5 and 6 based on Security and Data protection officer (DPO)
5. Are ample security precautions taken on storing the personal information?
a. Is the data that is stored encrypted and secure?.
b. Is the access to the data available to only the authorised personnel?
c. Is case of a breach are there systems in place to ensure that the breach does not cause any harm to the
data subject. If these precautions are not there is there a system in place to notify the supervisory board
and the data subject within 72hrs.
d. Is there a checklist to ensure that all the required information is transmitted during such an event?
6. Do we have a DPO who is in charge of looking into all the data?
a. Has the selected DPO contact been communicated to the supervisory board?
b. Does the data subjects have access to the DPO if needed?
Questions companies should ask
But it's just a list of
well behaved
kids!!!
Sorry Santa.. It's still
personal information
● http://ec.europa.eu/justice/data-
protection/reform/files/regulation_oj_en.pdf
● http://www.eugdpr.org/eugdpr.org.html
● https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf
● https://www.cloudlock.com/blog/eu-gdpr-vs-data-protection-
directive/
● http://viclarity.com/general-data-protection-regulation-gdpr/
REFERENCES

Mais conteúdo relacionado

Mais procurados

How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR readyPremier EPOS
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Zoodikers
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)RAKESH S
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
Do You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? ArticleDo You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? ArticleUlf Mattsson
 
General data protection
General data protectionGeneral data protection
General data protectionBrijeshR3
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and PrivacyVertex Holdings
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 

Mais procurados (20)

How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
Do You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? ArticleDo You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? Article
 
General data protection
General data protectionGeneral data protection
General data protection
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
Data Protection and Privacy
Data Protection and PrivacyData Protection and Privacy
Data Protection and Privacy
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 

Semelhante a How to get started with being GDPR compliant

12 steps to prepare for GDPR
12 steps to prepare for GDPR12 steps to prepare for GDPR
12 steps to prepare for GDPRGary Chambers
 
Are you GDPR ready for EU General Data Protection Regulation?
Are you GDPR ready for EU General Data Protection Regulation?Are you GDPR ready for EU General Data Protection Regulation?
Are you GDPR ready for EU General Data Protection Regulation?Fraser Hay
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Followetouches
 
Dave Lovatt | Our GDPR Journey
Dave Lovatt | Our GDPR JourneyDave Lovatt | Our GDPR Journey
Dave Lovatt | Our GDPR JourneyPro Mrkt
 
Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRPrecisely
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPRNeha Patel
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?Gareth Miller
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365 GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365 ayeshaurooj104
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidencePrecisely
 
GDPR Checklist Infographic
GDPR Checklist InfographicGDPR Checklist Infographic
GDPR Checklist InfographicConnexica
 

Semelhante a How to get started with being GDPR compliant (20)

GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
12 steps to prepare for GDPR
12 steps to prepare for GDPR12 steps to prepare for GDPR
12 steps to prepare for GDPR
 
2018 Client Briefing GDPR
2018 Client Briefing GDPR2018 Client Briefing GDPR
2018 Client Briefing GDPR
 
Are you GDPR ready for EU General Data Protection Regulation?
Are you GDPR ready for EU General Data Protection Regulation?Are you GDPR ready for EU General Data Protection Regulation?
Are you GDPR ready for EU General Data Protection Regulation?
 
GDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to FollowGDPR: the Steps Event Planners Need to Follow
GDPR: the Steps Event Planners Need to Follow
 
GDPR: Time to Act
GDPR: Time to ActGDPR: Time to Act
GDPR: Time to Act
 
Dave Lovatt | Our GDPR Journey
Dave Lovatt | Our GDPR JourneyDave Lovatt | Our GDPR Journey
Dave Lovatt | Our GDPR Journey
 
Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPR
 
A Brief Overview on GDPR
A Brief Overview on GDPRA Brief Overview on GDPR
A Brief Overview on GDPR
 
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM WorksGDPR: Where should you be right now? - Dennis Slattery, EDM Works
GDPR: Where should you be right now? - Dennis Slattery, EDM Works
 
Is your business GDPR ready?
Is your business GDPR ready?Is your business GDPR ready?
Is your business GDPR ready?
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365 GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
Are you GDPRed yet?
Are you GDPRed yet?Are you GDPRed yet?
Are you GDPRed yet?
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with Confidence
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
GDPR Checklist Infographic
GDPR Checklist InfographicGDPR Checklist Infographic
GDPR Checklist Infographic
 

Último

👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...rajveerescorts2022
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Roland Driesen
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfPaul Menig
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Centuryrwgiffor
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...amitlee9823
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756dollysharma2066
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 

Último (20)

👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...Boost the utilization of your HCL environment by reevaluating use cases and f...
Boost the utilization of your HCL environment by reevaluating use cases and f...
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Grateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdfGrateful 7 speech thanking everyone that has helped.pdf
Grateful 7 speech thanking everyone that has helped.pdf
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 

How to get started with being GDPR compliant

  • 1. HOW TO GET STARTED WITH BEING GDPR COMPLIANT BY SIDDHARTH RAM DINESH
  • 2. Where do I begin finding out about GDPR? What is GDPR? How would a company go about being GDPR compliant? Why is GDPR important? Who does GDPR affect ?
  • 3. GDPR … What is it ?
  • 4. “ The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and unify data protection for all individuals within the European Union (EU). “
  • 6. One Set of Rules Across the EU Personal Data Redefined New Individual Rights Mandatory Breach Notification Financial Repercussions Joint Responsibility Information Governance Truly Global Impact
  • 8. A generic process flow an organization could follow to achieve GDPR compliance before May 25, 2018
  • 9. Q2 2017 Q3 2017 Q4 2017 Q1 2018 Q2 2018 April May June July August September October November December January February March April May June Awareness and Communication Initiation Define policies and procedures Regulation date 25th May 2018 Current state assessment and plan Implement technology and business changes Gap and Risk Assessment Training Update Contracts Update privacy notices and consent GDPR PRocEss Flow TIMELINE
  • 11. MARKETING PROCUREMENT HRSUPPORTLEGAL IT RAISE AWARENESS INFORMATION HELD CONCENT INDIVIDUAL RIGHTS COMMUNICATING PRIVACY CHILDREN'S DATA DATA PROTECTION OFFICERS DATA BREACHES INTERNATIONAL LOCATIONS Company Horizontals Factors to check
  • 13. “The GDPR does not define the notion of “risk”, but the recitals and the substantive provisions include indications of the types of risks and harms to individuals to be considered.“ Some of the possible risks are: - Discrimination - Identity theft / fraud, financial loss - Reputation damage - Loss of confidentiality of personal data protected by professional secrecy - Processing large amounts of data affecting large numbers of individuals
  • 15. EdUCATE EMPLOYEES oN GDPR ● Make sure that decision makers and key people in your organisation are aware that the law is changing to the GDPR. ● They are likely to identify areas that could cause compliance problems under the GDPR.
  • 17. UPDATE OPERATIONAL pOLICIES Appoint a contact point for the data protection authority (DPA) and data subjects, and a data protection officer (DPO) to ensure processing operations are compliant. Update company operational policies to be GDPR compliant Create policies and rollout policies is a way that it’s as less disruptive as possible
  • 19. CHANGE MANAGEMENT AND COMMUNICATION Create a change management plan to incorporate and roll out all the required policy changes throughout the company Rollout change in policy to the customers updating them on the changes in regulations and privacy policy Update contracts with subcontractors and make sure they follow GDPR guidelines
  • 21. Fulfill compliance before May 2018 Be compliant as soon as possible to avoid last minute changes. Makes the organization’s functioning smooth and panic free. Buffer time would allow the company to perfect the systems and avoid errors after May 2018.
  • 22. Hypothesis: The questions are asked by a large hospital chain that is validating its GDPR compliance status. Questions 1 and 2 based on Consent 1. Is the data subject aware of the personal data we possess? a. Does the data we hold currently, post consent from the data subject? b. Are we using the personal data for any other purpose other than what we got consent for? c. Do we have a system/policy in place to handle consent (communicate, withdraw, update etc) 2. Do we have a system to process children's’ data? a. Is the data of children below the age of 16 being held post consent from their parents? b. Is the data used only for the purpose stated in the consent document? Questions companies should ask
  • 23. Questions 3 and 4 based on Data handling 3. Do we have a process to monitor where the data is being transferred? a. Is the data transferred to any 3rd party companies like insurance or banks? If so is only the relevant data transferred to them. b. Is the 3rd party company that we are dealing with GDPR compliant? c. Do we have a system in place to check and validate the compliance of the 3rd party companies d. Is the data sent to any 3rd party applications being monitored and validated? 4. If the data that we have is being processed for any other reason other than stated in the consent document, do we have a system to communicate that to the data subject? a. Validate if the information is held for any reasons mentioned in the GDPR document which exempts the need for consent Questions companies should ask
  • 24. Questions 5 and 6 based on Security and Data protection officer (DPO) 5. Are ample security precautions taken on storing the personal information? a. Is the data that is stored encrypted and secure?. b. Is the access to the data available to only the authorised personnel? c. Is case of a breach are there systems in place to ensure that the breach does not cause any harm to the data subject. If these precautions are not there is there a system in place to notify the supervisory board and the data subject within 72hrs. d. Is there a checklist to ensure that all the required information is transmitted during such an event? 6. Do we have a DPO who is in charge of looking into all the data? a. Has the selected DPO contact been communicated to the supervisory board? b. Does the data subjects have access to the DPO if needed? Questions companies should ask
  • 25. But it's just a list of well behaved kids!!! Sorry Santa.. It's still personal information
  • 26. ● http://ec.europa.eu/justice/data- protection/reform/files/regulation_oj_en.pdf ● http://www.eugdpr.org/eugdpr.org.html ● https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf ● https://www.cloudlock.com/blog/eu-gdpr-vs-data-protection- directive/ ● http://viclarity.com/general-data-protection-regulation-gdpr/ REFERENCES

Notas do Editor

  1. The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and unify data protection for all individuals within the European Union (EU). GDPR replaces the DPD (Data protection directive). Addresses the export of personal data outside the EU. The primary objectives of the GDPR are to give control back to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU. Regulation adopted on 27 April 2016. Applies from 25 May 2018 after a two-year transition period