GDPR enforcement begins

Slides:



Advertisements
Similar presentations
The EU General Data Protection Regulation Frank Rankin.
Advertisements

Your Code of Conduct: Data Protection & Compliance Your Code of Conduct: Data Protection & Compliance for Charities.
General Data Protection Regulation (EU 2016/679)
Data Protection Regulation
GDPR 12 POINTS 679/2016 DATA LEX 2016.
Tony Sheppard Mobile Guardian
General Data Protection Regulation (GDPR)
Data Protection Officer’s Overview of the GDPR
General Data Protection Regulations: The Key Changes
Accountability & Structured Privacy Management
The future of data protection: General Data Protection Regulation
Understanding EU GDPR from an Office 365 perspective
Microsoft 365 Get help with regulatory compliance
Presentation to GTMC on GDPR
General Data Protection Regulations: what you really need to know
Data Protection The Current Regime
General Data Protection Regulation (GDPR
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
GDPR Overview Gydeline – October 2017
General Data Protection Regulation: Turning the black into white
Microsoft Corporation
GDPR Overview Gydeline – October 2017
The European Union General Data Protection Regulation (GDPR)
Nina Barakzai November 2017
INTRODUCTION TO GDPR 19/09/2018.
Data protection reform:
GDPR Road map to Compliance.
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
Vikas Dewangan (Senior Technology Architect)
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
The General Data Protection Regulation (GDPR)
Data protection reform – update from the ICO
State of the privacy union
From DPA to GDPR: the key elements
The new data protection rules

General Data Protection Regulations
GDPR Overview and Use Cases.
General Data Protection Regulation
Data Protection and You
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR (General Data Protection Regulation)
Guide to overview of changes under GDPR ww.ZAKSIT.com
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
General Data Protection Regulations (GDPR) Training
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
Are you GDPR ready? Get help with regulatory compliance
Information Handling Research Student Induction Day
 GDPR Readiness Quiz Quick Insight: Quick Insight: Quick Insight:
The General Data Protection Regulation: Are You Ready?
The title: The implementation of Data Protection
General Data Protection regulation (GDPR)
General Date Protection Regulation
General Data Protection Regulation Q & A Session
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The supervision of personal data processing by EU institutions and bodies => data protection and privacy, why it matters, for you as citizens and as EU.
General Data Protection Regulation (GDPR)
GDPR Session
General Data Protection Regulation “11 months in”
Data Privacy by Design Expanding Security for bepress Users
General Data Protection Regulation
Information Governance
Getting Ready For GDPR Simon Marks Director
GDPR is here – are you ready?
Presentation transcript:

GDPR enforcement begins What is the GDPR? The General Data Protection Regulation (GDPR) is a new data protection framework that governs how organizations collect, process, and use personal data across all 28 EU member states. The GDPR takes effect in May 2018 and imposes new rules on organizations in the European Union (EU) and those that offer goods and services to people in the EU, or that collect and analyze data tied to people in the EU, no matter where the organizations are located. One Set of Rules for all companies collecting, storing, or using the personal data of people in the EU Penalties for Non-compliance: Up to 4% of last year’s global sales or €20 million, whichever is greater Applies to 100% 72 Hours — Time in which data breaches must generally be reported to supervisory authority of companies that collect or process personal data of people in the EU, even if the data is stored or used outside the EU DPO Required — Many businesses are required to appoint a Data Protection Officer, including those processing high volumes of personal data The GDPR gives consumers more control over the collection, processing, and retention of their personal data: Consumer Rights Company Responsibilities The RESPONSIBILITY to minimize data collection The RESPONSIBILITY to limit processing to the purpose for which data was collected The RESPONSIBILITY to conduct proactive assessments when processing consumer data The RESPONSIBILITY to record data processing activities and limit who can access consumer data The RESPONSIBILITY to report breaches without undue delay, typically 72 hours The RESPONSIBILITY to be transparent about what personal data they collect and how it is used The RIGHT to withdraw consent and have all data removed The RIGHT to correct errors The RIGHT to be notified if data is endangered The RIGHT to request data in a portable format and to transfer data between companies MAY 25 2018 GDPR enforcement begins 92% of US organizations say GDPR compliance is a top data protection priority 77% of US companies with more than 500 employees plan to spend at least $1 million on the GDPR 69% of companies say they plan to use a technology firm to help with the GDPR preparations Source: https://www.pwc.com/us/en/increasin-it- effectiveness/publications/assets/pwc- gdpr-series-pulse-survey.pdf Source: https://www.pwc.com/us/en/press- releases/2017/pwc-gdpr-compliance- press-release.html Source: https://www.pwc.com/us/en/increasing-it-effectiveness/publications/general-data-protection-regulation-gdpr-budgets.html Compliance 101 Communicate Use plain language to tell people who you are, explain why you need their data, how long it will be stored, and how it will be shared. Get Consent When required, obtain clear consent to data collection, and check age requirements for parental consent. Provide Access Allow people to access their data in a portable format, make corrections, and transfer it to other companies if they choose. Warn & Protect Provide notice of breaches when consumer data is at risk, and understand limits on processing special categories of sensitive data. Opt-Out & Remove Give people the opportunity to opt-out of direct marketing that uses their personal data and delete their data when they exercise their “right to be forgotten.” Profiling If you use data profiling to process applications for legally-binding agreements, you must inform consumers, provide a manual check of the process, and allow applicants to contest the decision if an application is denied. Privacy Risk Assessment Processing or storing data with a high risk to the privacy or rights of people in the EU? GDPR requires you to conduct a Data Protection Impact Assessment. Sensitive Personal Data The GDPR has heightened requirements for processing highly sensitive personal data, including: Race or ethnicity Political, religious or philosophical beliefs Health information Sexual preferences Trade union membership How to Get Started Learn Take advantage of our GDPR Foundations Training to learn more about requirements. Assess Complete our GDPR Readiness Assessment to determine how to proceed. Plan Work with our security and compliance experts to develop a GDPR roadmap for your organization. Contact us to learn more about how we can help simplify the impact of the GDPR on your organization. [Partner Name} [Partner Phone] [Partner URL] *This information is a commentary on the GDPR, as Microsoft interprets it, as of the date of publication. Application of GDPR is highly fact-specific, and not all aspects of GDPR are well-settled. This information should not be relied on as legal advice.