Privacy and Cyber Security for Payroll Pros: A Global Perspective

Slides:



Advertisements
Similar presentations
The Data Protection (Jersey) Law 2005.
Advertisements

1 Pertemuan 7 Points of Exposure Matakuliah:A0334/Pengendalian Lingkungan Online Tahun: 2005 Versi: 1/1.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Research Paper Presentation Software Engineering in agent systems.
The Data Protection Act 1998 The Eight Principles.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
What is personal data? Personal data is data about an individual which they consider to be private.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
Data Protection and research Rachael Maguire Records Manager.
Session 12 Information management and security. 1 Contents Part 1: Introduction Part 2: Legal and regulatory responsibilities Part 3: Our Procedures Part.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
The EU General Data Protection Regulation Frank Rankin.
Data protection—training materials [Name and details of speaker]
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
General Data Protection Regulation (EU 2016/679)
The Data Protection Act 1998
The Data Protection Act 1998
Information Management in Government: A Legal Perspective
Making the Connection ISO Master Class An Overview.
Suggestion for Summarizing Process of the Principles
CISI – Financial Products, Markets & Services
Luca De Matteis Justice counsellor (criminal law, data protection)
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Presentation to GTMC on GDPR
Data Protection The Current Regime
General Data Protection Regulation
Data Protection Act.
Convention108 in a snapshot
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
BUILDING A PRIVACY AND SECURITY PROGRAM FOR YOUR NON-PROFIT
International Regulatory Trends
GDPR Readiness Project
Privacy and Security in the Employment Relationship
The Data Protection Act 1998
Data Protection Update – GDPR or bust
GDPR Overview GDPR - General Data Protection Regulations
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
6 Principles of the GDPR and SQL Provision
GDPR 101 and ucsb’s response
The General Data Protection Regulation (GDPR)
New Data Protection Legislation
GDPR and Health and Safety
Data Protection Act.
Information Governance
G.D.P.R General Data Protection Regulations
The GDPR and research data
FEK årskonferanse 28. februar 2018.

General Data Protection Regulation
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
A whistle stop tour of GDPR
General Data Protection Regulations 2018
General Data Protection Regulations (GDPR) Training
What is the Data Protection Act (DPA)? 1998
The General Data Protection Regulation Six months on – What’s changed
The General Data Protection Regulation: Are You Ready?
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
#eaThinkData Get Ready for GDPR #eaThinkData.
Hot Topic 1: GDPR and Traffic Data Systems
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Legislative Response to Data Inferences
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation Community Councils
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

Privacy and Cyber Security for Payroll Pros: A Global Perspective Steve Sheinberg General Counsel & SVP, Privacy and Security

Payroll Privacy is…Confidentiality Workplace policies that lawfully handle discussions of salary Have procedures for every request Physical set up for payroll professionals

Payroll Privacy is…Cyber Security Employees are the key threat vector Teach social engineering defense Use 2FA good password complexity and change Protect yourself with vendors Update software, install patches Encrypt Segregate data Plan for off-boarding Plan to identify and mitigate breaches Payroll data breach reporting process Review agreements w/ 3rd parties for notification and process Notification to employees

Payroll Privacy is…Legal Compliance EU/GDPR: Applies to all business within EU, including handling of EU-based employee data from outside EU Security and Privacy are intertwined: “the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks represented by the processing” The above security recommendations = obligatory

GDPR: EU Law and Good Policy Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject. Personal data must be collected only for specified, explicit and legitimate purposes. It must not be further processed in any manner incompatible with those purposes. Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed “minimized.” Personal data must be accurate and, where necessary, kept up to date. Personal data must not be kept in a form which permits identification of data subjects for longer than is necessary for the purposes for which the data is processed. Personal data must be processed in a manner that ensures its appropriate security.

Other Jurisdictions Japan China Brazil Russia India

Thank you!