Download presentation
Presentation is loading. Please wait.
Published byStewart Hodges Modified over 6 years ago
1
GDPR Project Implementation Theory and Practice
Goran CHAMUROVSKIMBA, CISA, CRISC, PMP, ITIL, CIPP/E Managing Director of INTEGRA Solution
2
Outline GDPR Introduction Project Implosion Regulation vs Standard
Delivery of Org change Risk multiple facets Complexity The Georgia Tech seminar was held October 9-10, The university supported the meeting, and the seminar was on advanced project management concepts. It was during that event that those who managed projects—project managers—were asked to join a new organization—the Project Management Institute. But it didn’t just happen overnight. It took five years for PMI’s founders to move from the idea of a professional project management association to the formation of PMI. Between February and October 1969, a constitution and bylaws were drafted and financial support for the startup was solicited. PMI was incorporated in Pennsylvania. USA The name was officially registered as Project Management Institute (after briefing considering “American Institute of Project Management,” The founders quickly discarded that name as one of their original objectives was to be a global organization serving project, program and portfolio managers wherever they live and work. )
3
GDPR short introduction
PD protection Scope Lawful basis for processing Responsibility and accountability Implementing measures
4
Project Implosion Risk Based Projects Inherent Risk Gap Assessment
Implementation Project Implosion Risk Based Projects Inherent Risk Gap Assessment High level Risk Assessment Control Risk
5
Regulation vs Standard
GDPR Regulation 27001 29100 NIST 20000 Data subject rights and freedoms Certification scheme Applicability and size of the organization High Risk processing activities
6
Delivery of ,… Sustainability Maturity Embedding Product vs service
Org Change Maturity Product vs service Service vs organizational change Maturity assessment Embedding Sustainability
7
Risk multiple facets Opportunity D&D Threat RTP DPIA Risk
A threat or opportunity Data protection Impact Assessment By design and by default principle Risk Treatment Plan Investment vs cost justification
8
Project complexity Interdisciplinary Involving all stakeholders
Effectivenes Stakeholders Competencies Interdisciplinary Involving all stakeholders New requirements (Pseudonymisation, Right of access, Right to erasure Data protection officer Competencies Data breaches and sanctions
9
Thanks
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.