Download presentation
Presentation is loading. Please wait.
1
GDPR, PCS UG 15th May 2018, Vienna
2
GDPR in general
3
4 years 90 pages Introduction
24 April 2018 The EU’s General Data Protection Regulation (GDPR) is maybe the most comprehensive and complex data privacy regulation in the world. It is an impressive act of legislation. Some people call it a great law. Other don’t. more than 55,000 words Almost 90 pages 4 years of negotiations between many interested parties Datenschutzgesetz (DSG)
4
General Data Protection Regulation (GDPR) in short
24 April 2018 General Data Protection Regulation (GDPR) in short What? The GDPR stands for Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data The GDPR protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data. Why? It shall be binding in its entirety and directly applicable in all Member States (=NO transposition in national law) How? When? It shall apply from 25 May 2018
5
It is all about the EU citizens privacy
24 April 2018 What is all about? It is all about the EU citizens privacy The business supervisory authority in Austria Balance? administrative fines up to € 20 million The state Article 13 Right to be informed Article 15 Right of access Article 16 Right to rectification Article 17 Right to erasure (‘Right to be Forgotten’) Article 18 Right to restrict processing Article 19 Right the recipients to be informed Article 20 Right to data portability Article 21 Right to object
6
RNE External Dimension – Scale
20 April 2018 RNE External Dimension – Scale CIP 91 TCR 70 CCS 222 10 128 and counting Individuals’ personal data (as of 30 March 2018) RNE Data Controller TIS 3284 PCS 1782 CMS 4262 CIS 143 OTRS 320 First name and last name Username/Password address Phone number Employer Gender
7
PCS GUI
8
Agreement Each user that has already an account, after their login to PCS, must confirm for the first and last time something link that (drafted by our Legal Advisor): I have read the RNE privacy notice and agree to the processing of my personal data by RNE according to the GDPR (General Data Protection Regulation) I agree that RNE can send to my address the PCS related messages (e.g. newsletter). You can withdraw your agreement at any time. In this case please contact us at I AGREE The link of the privacy notice will point to RNE PCS website. Constraints: No default value for the check-boxes “I agree” button should be disabled until the first check-box is not selected. From this point of view the second check-box is considered as optional, but there should not be any indication on the screen whether one of them is mandatory and/or optional If they don’t agree, they cannot proceed in the system. They must agree or log out. (optional) When they agreed, we should send them an about the confirmation. Like we send to the C-OSS for accepting GTC. It’s kind of similar case.
9
User profile adjustment
Date and time of their agreement with the GDPR should be stored in the database. Also the indication, if they are interested in the Newsletter, should be stored. User profile information should be extended with the date of creation of the account. User profile information should have the last update date Name Company Password is encrypted. Not possible to check a user’s password, only to reset. Phone Password*
10
PCS User administration process
11
New account/Change company
12
User administration process
Link to webform: User Fulfils the data himself/herself Confirms the truth of the information Submits request Confirmation to the user with the entered information Information to PCS Support PCS Support: Informs the user about the created credentials
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.