THE IMPACT OF DATA PROTECTION RULES ON CORPORATE INFO SECURITY AND INCIDENT RESPONSE MANAGEMENT – The Energy sector CEER Cybersecurity Workshop Massimo.

Slides:



Advertisements
Similar presentations
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Advertisements

© Obelis s.a CODE OF CONDUCT of Authorised Representative services under the Council Directive 93/42/EEC, Directive 98/79/EC and Council Directive.
European Data Protection Supervisor Pharmaceutical Regulatory & Compliance Congress, Brussels, 7 June 2007 European Privacy and Data Protection Policy.
The EU General Data Protection Regulation Frank Rankin.
-1- WORKSHOP ON DATA PROTECTION AND DATA TRANSFERS TO THIRD COUNTRIES Technical and organizational security measures Skopje, 16 May - 17 May 2011 María.
General Data Protection Regulation (EU 2016/679)
Data Protection Regulation
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
Unpacking the European Commission General Data Protection Regulation
GDPR (General Data Protection Regulation)
Understanding EU GDPR from an Office 365 perspective
Ireland’s transition towards the GDPR
Microsoft 365 Get help with regulatory compliance
WORLD OF CLOUD COMPUTING AFTER GDPR challenges, opportunities and the unknown Matjaž Drev, MA. National Supervisor for Personal Data Protection, Information.
Presentation to GTMC on GDPR
General Data Protection Regulation (GDPR)
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data protection reform:
Radar Watchkeeping: Have you monitored your Communication department’s radar to avoid collisions with the new Regulation? 43rd EDPS-DPO meeting, 31 May.
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
Cyberforum 2018 March 8, 2018 Los Angeles GDPR & SECURITY
GDPR - New Data Protection Regulation
Introduction to GDPR 09/11/2018.
GDPR and paper records Why it’s not all cyber and fines Gary Shipsey
Dan Tofan | Expert in NIS 21st Art. 13a WG| LISBON |
Update from the ITP Sector
Software for ambitious enterprises
State of the privacy union
Appropriate Data Sharing in Health and Social Care
The GDPR and research data
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
Protection of Personal Information Bill: An International Perspective
GDPR – Practical Implementation Managing contracts, procurement and relationships with suppliers Terry Brewer Chief Executive.
General Data Protection Regulation
The National Working Group
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation (GDPR)
GDPR - New Data Protection Regulation
GDPR For The Voluntary Sector
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
Data Protection and Audit
GDPR Workshop MEU Symposium Prague 2018
Welcome!.
General Data Protection Regulations 2018
Data transfers to non-EU countries under the new GDPR
GDPR enforcement begins
The activity of Art. 29. Working Party György Halmos
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
By The Data Protection Commissioner
Governing the risk of GDPR compliance
GDPR & Accountability ISACA Ireland Annual Conference 2018
 GDPR Readiness Quiz Quick Insight: Quick Insight: Quick Insight:
Data protection by design, Art.25.1 of the GDPR
General Data Protection regulation (GDPR)
The EDPS: competences and processing of personal data in EU funds
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Fines, Sanctions and Compensation The teeth in the GDPR & Data Protection Act 2018 by Simon McGarr, CIPP/E Data Compliance Europe.
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
The supervision of personal data processing by EU institutions and bodies => data protection and privacy, why it matters, for you as citizens and as EU.
General Data Protection Regulation “11 months in”
GDPR Workshop – Partnerships for Jewish Schools
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

THE IMPACT OF DATA PROTECTION RULES ON CORPORATE INFO SECURITY AND INCIDENT RESPONSE MANAGEMENT – The Energy sector CEER Cybersecurity Workshop Massimo Attoresi (European Data Protection Supervisor) IT Policy officer – Data Protection Officer Friday 21 june 2019

The GDPR and the energy sector Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data..... Energy sector and processing of personal data: data provided by the customer for contract management and billing data collected at the smart meter’s level (readings); data of the smart house (in case the energy operator is involved); data provided by the customer or others for customer care and business improvement purposes; data and infrastructure security; ...... Legal bases: law, legitimate interest, consent

Cybersecurity rules in the GDPR Art.32 - security of processing of personal data The mandatory risk-based approach The role of codes of conduct and certification mechanisms. Art. 33 - notification of a personal data breach to the supervisory authority RISK for data subjects: notification to the SA within 72 hours Art. 34 – communication of a personal data breach to the data subject HIGH RISK for data subjects: communication to the data subjects involved without undue delay

GDPR, corporate info security and incident management What are the new elements integrated? Difference of nature of risk to be assessed and notification obligations The role of codes of conduct and certification mechanisms. Overarching rule: art.25 on data protection by design and by default Security of personal data by design and by default, too ! Protection of confidentiality, integrity and availability (and non-repudiation) of personal data as an early requirement and throughout the project lifecycle. This approach benefits non-personal data, too: the whole project State of the art of protective measures The experience of the BAT for the 10 minimum functional requirements of smart metering systems.

Then...what shall I change in my organisation? Do GDPR rules oblige me to have a parallel info security and incident management process? Which of the three replies would you consider? Yes. A complete new assessment of risks for personal data needs to be carried out and a different process to be set up for incident No, I need just to integrate the new notification and communication requirements in case of a personal data breach No. I need to consider also the risks for the individuals whose data are processed (further to those to corporate assets and other compliance obligation), and the new notification and communication requirements in case of a breach of personal data security. Looking for shared, processes integrating the many compliance obligations within the industry. The way forward? Personal views: Industry and their representative to play a proactive, by proposing and sharing best practices and processes Codes of conducts, integrating how to deal with compliance requirements, may play an important roles Indeed Member States need to contribute resources to facilitate all this, especially when it comes to SMEs

Thank you! For more information: www.edps.europa.eu edps@edps.europa.eu @EU_EDPS EDPS European Data Protection Supervisor

? ? ? ? Any questions ? ? ? ? ?