Data Mapping On the Journey to Accountability

Slides:



Advertisements
Similar presentations
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Advertisements

The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
Table of Contents. Lessons 1. Introduction to HIPAA Go Go 2. The Privacy Rule Go Go.
DON Code of Privacy Act Fair Information Principles DON has devised a list of principles to be applied when handling Protected Personal Information (PPI).
The EU General Data Protection Regulation Frank Rankin.
Data protection—training materials [Name and details of speaker]
Your Code of Conduct: Data Protection & Compliance Your Code of Conduct: Data Protection & Compliance for Charities.
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
Preparing for a data protection audit 28 September 2017
GDPR Module 3: Accountability and Governance
Private sector and GDPR
Viewing the GDPR Through a De-Identification Lens
Deployment of a DPO Niamh Gavin AIB Data Protection Legal
Presentation to GTMC on GDPR
ACC Annual Meeting Washington DC
General Data Protection Regulation (GDPR
General Data Protection Regulation
Museums + Heritage webinar, 30 November 2017
GDPR Readiness Project
GDPR Overview Gydeline – October 2017
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
Head of Information Management Services Crown Worldwide
Data protection reform:
Data Protection & Freedom of Information- An Introduction
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
Cyberforum 2018 March 8, 2018 Los Angeles GDPR & SECURITY
GDPR - New Data Protection Regulation
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
The Audit Function.
Preparing for the EU General Data Protection Regulation
Data protection reform – update from the ICO
State of the privacy union
Information Governance
From DPA to GDPR: the key elements
GDPR Overview and Use Cases.
General Data Protection Regulation
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Project Start-up This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No
IMPLICATIONS OF GDPR ROBERT BELL.
Data Protection and Audit
Welcome!.
Data transfers to non-EU countries under the new GDPR
GDPR enforcement begins
The General Data Protection Regulation Six months on – What’s changed
GDPR & Accountability ISACA Ireland Annual Conference 2018
Lesson 1  7 Basic Components of an Effective Compliance Plan
 GDPR Readiness Quiz Quick Insight: Quick Insight: Quick Insight:
The General Data Protection Regulation: Are You Ready?
GENERAL DATA PROTECTION REGULATION 2016 (GDPR)
Project Start-up This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No
General Data Protection regulation (GDPR)
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Session 4: Data Mapping and Data Subject Rights
Data Mapping & Data Subject Rights
Data Protection What can I do? GDPR Principles General Data Protection
Session 4: Data Mapping and Data Subject Rights
General Data Protection Regulation “11 months in”
General Data Protection Regulations What is it Why is it important
GDPR Workshop – Partnerships for Jewish Schools
Information Governance
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

Data Mapping On the Journey to Accountability

87 24 35k Trainline today Train companies Countries Stations Trainline || Private & Confidential

What does the GDPR say? Recital 82 In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be obliged to cooperate with the supervisory authority and make those records, on request, available to it, so that it might serve for monitoring those processing operations Categories of data Name and contact details Categories of recipient Security measures Purposes of processing Transfers & safeguards Retention Trainline || Private & Confidential

Data Mapping - a foundational activity Privacy notices Individual rights Data breach DPIAs Privacy by design Minimisation Trainline || Private & Confidential

Practical considerations When to start? When are we finished? Who is involved? How to maintain records? Manual vs automation? Trainline || Private & Confidential

Insights on approach Trainline || Private & Confidential

Benefits Better data Privacy maturity Accountability Quicker response GDPR enablement Trainline || Private & Confidential

Accountability Accountability Appropriate measures Data mapping DPO Privacy by design DPIA Codes of conduct The new accountability principle in Article 5(2) requires you to demonstrate that you comply with the principles and states explicitly that this is your responsibility. Trainline || Private & Confidential

QUESTIONS? Trainline || Private & Confidential