SlideShare ist ein Scribd-Unternehmen logo
1 von 19
Downloaden Sie, um offline zu lesen
3rd Party Risk Management- GDPR
GDPR summit RDS - May 30th 2018
Partners in
Supplier
Management
Solutions
We are trusted advisors and partners for developing and implementing world-class
sustainable 3rd Party solutions
Brian is Executive Director of Verego and CEO of Clearstream Solutions, a
leading independent supply chain consultancy which he founded in 2008.
Clearstream’s services help its clients to manage and report supply chain
sustainability and compliance. Current global clients include Microsoft,
Symantec, Honeywell, Verego, Teleplan, Arvato, Veritas and Vodafone.
Brian has 25 years’ experience in global supply chain management,
particularly in the areas of Electronics, Media, Print & Packaging. He has a
degree in Economics from Trinity College, a Certificate in Sustainable
Management from BSI Group and is currently studying the Circular
Economy at TU Delft.
Introducing Clearstream and Partners
Anne Quinn, Clearstream Associate, recently completed a 17-year career at
Microsoft, where she led global programs in Global Operations, Customer
Service and Support, Finance, and Procurement. Most recently, Anne was the
Director of Supplier Risk Management & Compliance and drove supplier
compliance to Microsoft's Privacy and Security requirements, including a
GDPR readiness program. She also launched a revised Supplier Code of
Conduct Training Program for 40,000+ suppliers, and managed Procurement’s
Anti-Corruption Vetting program. Anne has recently earned the ANSI-
accredited Certified Information Privacy Professional/Europe (CIPP/E). Anne
will be utilizing her extensive experience to provide consultancy to companies
on 3rd party risk management under GDPR
• Clearstream Solutions is a leading supply chain and sustainability services solution provider.
• We assist organizations to measure and implement best-in-class sustainable practice in their
businesses, products and supply chains.
• Our solutions deliver tangible, measurable savings for our clients who include some of the leading
private and public sector organizations in Ireland and around the world.
• Clearstream also provides consultancy services and tools to help our clients implement
Responsible Sourcing programs in their Supply Chains and Outsourcing operations (Verego)
• Clearstream has won a national Green Award and an Envirocom Award. We also won first place in
the last Dublin Chamber Sustainable Business Challenge. We are the local Ireland partner of CDP
global.
About Clearstream Solutions
Some Clients:
3rd Party Risk Management and GDPR
Face Book-Cambridge Analytica Data Breach
“Cambridge Analytica Exploited the Facebook Data of Millions”.
Up to 87 million people impacted by Facebook data breach!
3rd Party Relationships/Risks
The frequency and scale of third party use has increased
Third party service providers are the most likely source of data breach,
implicated in over 60% of all incidents
Relationship Maturity Indicators and Lifecycle Management can help to
mitigate risk
There is now
increased
regulatory focus
on how
organization's are
managing 3rd
parties
Decreased Risk
Increased Risk
Enhanced personal privacy rights
Increased obligations for protecting data
Mandatory breach reporting
Significant penalties for non-compliance
The General Data Protection
Regulation (GDPR) imposes new
rules on organizations in the European
Union (EU) and those that offer goods
and services to people in the EU, or that
collect and analyze data tied to EU
residents, no matter where they are
located.
The General Data Protection Regulation
The GDPR has specifically called out the controller/processor relationship responsibilities
GDPR– Article 28 Controller/Processor Relationship
Definition of a processor: ‘processor’ shall mean a natural or legal person, public authority,
agency or any other body which processes personal data on behalf of the controller
The intention of Art. 28 is to flow down the security principle and the security requirements into
the processor’s organization and through the supply chain to sub-processors
GDPR– Article 28 Controller/Processor Relationship
Regardless of the allocation of responsibility in supplier contracts, data
subjects are entitled to enforce their rights against both the data
controller and the processor(s)
✓ Identify 3rd party personal data
handling -highlighting special
categories of personal data
✓ Conduct risk analysis -
severity/probability model
✓ Update 3rd party contracts to
ensure compliance to your
company privacy program/GDPR
✓ Consider Supplier GDPR
compliance attestations
✓ Vet new suppliers - walk away if
not GDPR compliant!
Immediate
▪ Create supplier pre-selection
due diligence program
▪ Ensure contract templates are
valid and up to date
▪ Develop supplier assurance
program (assessments/audits)
▪ Closed loop corrective action
▪ Internal awareness/alignment
across the organization
▪ Ensure demonstrable intent in
relation to supplier program
Futureplans
GDPR – What do I need to do?
What constitutes “sufficient guarantee” and how can this be measured?
VEREGO: Your Partner in Assessing Third Party Risk - Due Diligence
Our
Platform
We
Assess
We
Review
▪ Online Supplier Reporting Platform
▪ Transparency for both Suppliers and Buyers
▪ Immediate communication and information exchange
▪ Reporting Capabilities contained within Platform
▪ Demonstrates Due Diligence
▪ Option for response Review by Independent 3rd Party
Streamlined
Supplier
Assessments
Ongoing
Excellence
in Data
Protection
Framework for
Ongoing
Management
▪ Standardized Questionnaire available or optional
customized buyer GDPR Assessment
▪ Assessment Report on Performance and Risk
Compliance dashboard
The compliance dashboard
enables the Buyer to track
Suppliers as they register
and publish GDPR
information through
SupplierPortal.
All statistics are dependent
on the chosen settings,
meaning the compliance
status of your suppliers can
be analyzed and reported at
anytime.
Questionnaire analysis (option 2)
The questionnaire analysis
dashboard enables the
Buyers to track the
completion rate of all the
questionnaires, including
GDPR.
The flag status shows if
suppliers have triggered risk
flags in any of the
questionnaires.
By clicking on individual
questionnaires, Buyers can
see the status of each
supplier and if any flags
have been raised.
View supplier GDPR responses
Each supplier profile
contains multiple tabs of
information for that
supplier.
GDPR responses can be
reviewed and scored, and
supporting documents
downloaded.
Risk flags
Flags are set for high risk
GDPR non-compliance
issues.
When a supplier publishes
their response, users are
alerted if any flags have
been raised.
Performance scorecards
Through the GDPR
scorecard a suppliers
performance can be
calculated in relation to
other suppliers.
GDPR Audit – Due Diligence to identify GAP
GDPR data audits provided
standardised review of all
supplier responses.
PDF versions of audits are
available for distribution,
and a database of all
historical audits is held in
the system.
If required, third parties can
be given access to
designated suppliers for
more detailed
auditing/review.
DCU Alpha Campus
Old Finglas Rd, Glasnevin
Dublin 11
Phone: +353 1 297 3390
Web: www.clearstreamsolutions.ie
brian@clearstreamsolutions.ie

Weitere ähnliche Inhalte

Was ist angesagt?

Cloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management PerspectiveCloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management PerspectiveArgyle Executive Forum
 
EAI Compliance Infographic
EAI Compliance InfographicEAI Compliance Infographic
EAI Compliance InfographicIdeba
 
Regulatory Impact Analysis - Law & Economics course
Regulatory Impact Analysis - Law & Economics courseRegulatory Impact Analysis - Law & Economics course
Regulatory Impact Analysis - Law & Economics courseWilliam Byrnes
 
GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013FixNix Inc.,
 
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...DVV Solutions Third Party Risk Management
 
iKnow Solutions Laura Eisenhardt
iKnow Solutions Laura EisenhardtiKnow Solutions Laura Eisenhardt
iKnow Solutions Laura EisenhardtBigDataExpo
 
Healthcare outsourcing
Healthcare outsourcing Healthcare outsourcing
Healthcare outsourcing WGroup
 
Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...Chris Doolittle
 
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsTeleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsChris Doolittle
 
lce2011_paper_KERP
lce2011_paper_KERPlce2011_paper_KERP
lce2011_paper_KERPNick Stein
 

Was ist angesagt? (16)

Cloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management PerspectiveCloud Securiy: A Vendor Risk Management Perspective
Cloud Securiy: A Vendor Risk Management Perspective
 
Thematic compliance
Thematic complianceThematic compliance
Thematic compliance
 
Data Portability and Interoperability – SWIRE – June 2021 OECD discussion
Data Portability and Interoperability – SWIRE – June 2021 OECD discussionData Portability and Interoperability – SWIRE – June 2021 OECD discussion
Data Portability and Interoperability – SWIRE – June 2021 OECD discussion
 
EAI Compliance Infographic
EAI Compliance InfographicEAI Compliance Infographic
EAI Compliance Infographic
 
Regulatory Impact Analysis - Law & Economics course
Regulatory Impact Analysis - Law & Economics courseRegulatory Impact Analysis - Law & Economics course
Regulatory Impact Analysis - Law & Economics course
 
DJM_Bio[1]
DJM_Bio[1]DJM_Bio[1]
DJM_Bio[1]
 
GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013GRC 101 ISACA Bengaluru on 28th Dec 2013
GRC 101 ISACA Bengaluru on 28th Dec 2013
 
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
Building the Business Case for TPRM - DVV Solutions Breakfast Briefing March ...
 
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
 
Data Portability and Interoperability –KRÄMER – June 2021 OECD discussion
Data Portability and Interoperability –KRÄMER – June 2021 OECD discussionData Portability and Interoperability –KRÄMER – June 2021 OECD discussion
Data Portability and Interoperability –KRÄMER – June 2021 OECD discussion
 
iKnow Solutions Laura Eisenhardt
iKnow Solutions Laura EisenhardtiKnow Solutions Laura Eisenhardt
iKnow Solutions Laura Eisenhardt
 
PPT SCM Functions
PPT SCM FunctionsPPT SCM Functions
PPT SCM Functions
 
Healthcare outsourcing
Healthcare outsourcing Healthcare outsourcing
Healthcare outsourcing
 
Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...Addressing analytics, data warehouse and Big Data challenges beyond database ...
Addressing analytics, data warehouse and Big Data challenges beyond database ...
 
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR RequirementsTeleran Data Protection - Addressing 5 Critical GDPR Requirements
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
 
lce2011_paper_KERP
lce2011_paper_KERPlce2011_paper_KERP
lce2011_paper_KERP
 

Ähnlich wie Tech Connect Live 30th May 2018 ,GDPR Summit Anne quinn

Questions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfQuestions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfinfosecTrain
 
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬priyanshamadhwal2
 
A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103DVV Solutions Third Party Risk Management
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskTrustArc
 
Supply chain risks
Supply chain risksSupply chain risks
Supply chain risksNeik Lee
 
Overcoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOvercoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOnRamp
 
Security, Compliance Loss Prevention Part 13.pptx
Security, Compliance  Loss Prevention Part 13.pptxSecurity, Compliance  Loss Prevention Part 13.pptx
Security, Compliance Loss Prevention Part 13.pptxSheldon Byron
 
What is a data protection impact assessment? what are the essential stages to...
What is a data protection impact assessment? what are the essential stages to...What is a data protection impact assessment? what are the essential stages to...
What is a data protection impact assessment? what are the essential stages to...Infinity Legal Solutions
 
What is a data protection impact assessment?
What is a data protection impact assessment?What is a data protection impact assessment?
What is a data protection impact assessment?Infinity Legal Solutions
 
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...DVV Solutions Third Party Risk Management
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013Nidhi Gupta
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013Nidhi Gupta
 
Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Sean Bailey
 
Digital defence ds-vciso-supplychain
Digital defence ds-vciso-supplychainDigital defence ds-vciso-supplychain
Digital defence ds-vciso-supplychainShawn Brown
 
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment QuestionnairesThird-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment QuestionnairesCorporater
 

Ähnlich wie Tech Connect Live 30th May 2018 ,GDPR Summit Anne quinn (20)

Questions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfQuestions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
 
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
 
Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19 Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19
 
A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103A Comprehensive Approach To Third Party Risk Management White Paper 20180103
A Comprehensive Approach To Third Party Risk Management White Paper 20180103
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
Supply chain risks
Supply chain risksSupply chain risks
Supply chain risks
 
Overcoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security ModelOvercoming Hidden Risks in a Shared Security Model
Overcoming Hidden Risks in a Shared Security Model
 
Security, Compliance Loss Prevention Part 13.pptx
Security, Compliance  Loss Prevention Part 13.pptxSecurity, Compliance  Loss Prevention Part 13.pptx
Security, Compliance Loss Prevention Part 13.pptx
 
What is a data protection impact assessment? what are the essential stages to...
What is a data protection impact assessment? what are the essential stages to...What is a data protection impact assessment? what are the essential stages to...
What is a data protection impact assessment? what are the essential stages to...
 
What is a data protection impact assessment?
What is a data protection impact assessment?What is a data protection impact assessment?
What is a data protection impact assessment?
 
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
DVV Solutions Central Bank of Ireland Outsourcing discussion paper response 1...
 
Supply management 1.1.pdf
Supply management 1.1.pdfSupply management 1.1.pdf
Supply management 1.1.pdf
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit
 
Digital defence ds-vciso-supplychain
Digital defence ds-vciso-supplychainDigital defence ds-vciso-supplychain
Digital defence ds-vciso-supplychain
 
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment QuestionnairesThird-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
 
The Vital Role of Data Privacy and Security in SaaS Development in Europe.pdf
The Vital Role of Data Privacy and Security in SaaS Development in Europe.pdfThe Vital Role of Data Privacy and Security in SaaS Development in Europe.pdf
The Vital Role of Data Privacy and Security in SaaS Development in Europe.pdf
 

Kürzlich hochgeladen

Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challengeshemanthkumar470700
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon investment
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 MonthsIndeedSEO
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Cannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannaBusinessPlans
 
Buy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified Binance Account
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
New 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateNew 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateCannaBusinessPlans
 
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGParadip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGpr788182
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptxnandhinijagan9867
 
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030tarushabhavsar
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptxRoofing Contractor
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
Falcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingNauman Safdar
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...meghakumariji156
 

Kürzlich hochgeladen (20)

Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business Potential
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Cannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 Updated
 
Buy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From SeosmmearthBuy Verified TransferWise Accounts From Seosmmearth
Buy Verified TransferWise Accounts From Seosmmearth
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
New 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateNew 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck Template
 
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGParadip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030Over the Top (OTT) Market Size & Growth Outlook 2024-2030
Over the Top (OTT) Market Size & Growth Outlook 2024-2030
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptx
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Falcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial WingsFalcon Invoice Discounting: Tailored Financial Wings
Falcon Invoice Discounting: Tailored Financial Wings
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for Viewing
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
 

Tech Connect Live 30th May 2018 ,GDPR Summit Anne quinn

  • 1. 3rd Party Risk Management- GDPR GDPR summit RDS - May 30th 2018
  • 2. Partners in Supplier Management Solutions We are trusted advisors and partners for developing and implementing world-class sustainable 3rd Party solutions Brian is Executive Director of Verego and CEO of Clearstream Solutions, a leading independent supply chain consultancy which he founded in 2008. Clearstream’s services help its clients to manage and report supply chain sustainability and compliance. Current global clients include Microsoft, Symantec, Honeywell, Verego, Teleplan, Arvato, Veritas and Vodafone. Brian has 25 years’ experience in global supply chain management, particularly in the areas of Electronics, Media, Print & Packaging. He has a degree in Economics from Trinity College, a Certificate in Sustainable Management from BSI Group and is currently studying the Circular Economy at TU Delft. Introducing Clearstream and Partners Anne Quinn, Clearstream Associate, recently completed a 17-year career at Microsoft, where she led global programs in Global Operations, Customer Service and Support, Finance, and Procurement. Most recently, Anne was the Director of Supplier Risk Management & Compliance and drove supplier compliance to Microsoft's Privacy and Security requirements, including a GDPR readiness program. She also launched a revised Supplier Code of Conduct Training Program for 40,000+ suppliers, and managed Procurement’s Anti-Corruption Vetting program. Anne has recently earned the ANSI- accredited Certified Information Privacy Professional/Europe (CIPP/E). Anne will be utilizing her extensive experience to provide consultancy to companies on 3rd party risk management under GDPR
  • 3. • Clearstream Solutions is a leading supply chain and sustainability services solution provider. • We assist organizations to measure and implement best-in-class sustainable practice in their businesses, products and supply chains. • Our solutions deliver tangible, measurable savings for our clients who include some of the leading private and public sector organizations in Ireland and around the world. • Clearstream also provides consultancy services and tools to help our clients implement Responsible Sourcing programs in their Supply Chains and Outsourcing operations (Verego) • Clearstream has won a national Green Award and an Envirocom Award. We also won first place in the last Dublin Chamber Sustainable Business Challenge. We are the local Ireland partner of CDP global. About Clearstream Solutions
  • 5. 3rd Party Risk Management and GDPR
  • 6. Face Book-Cambridge Analytica Data Breach “Cambridge Analytica Exploited the Facebook Data of Millions”. Up to 87 million people impacted by Facebook data breach!
  • 7. 3rd Party Relationships/Risks The frequency and scale of third party use has increased Third party service providers are the most likely source of data breach, implicated in over 60% of all incidents Relationship Maturity Indicators and Lifecycle Management can help to mitigate risk There is now increased regulatory focus on how organization's are managing 3rd parties Decreased Risk Increased Risk
  • 8. Enhanced personal privacy rights Increased obligations for protecting data Mandatory breach reporting Significant penalties for non-compliance The General Data Protection Regulation (GDPR) imposes new rules on organizations in the European Union (EU) and those that offer goods and services to people in the EU, or that collect and analyze data tied to EU residents, no matter where they are located. The General Data Protection Regulation The GDPR has specifically called out the controller/processor relationship responsibilities
  • 9. GDPR– Article 28 Controller/Processor Relationship Definition of a processor: ‘processor’ shall mean a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller The intention of Art. 28 is to flow down the security principle and the security requirements into the processor’s organization and through the supply chain to sub-processors
  • 10. GDPR– Article 28 Controller/Processor Relationship Regardless of the allocation of responsibility in supplier contracts, data subjects are entitled to enforce their rights against both the data controller and the processor(s)
  • 11. ✓ Identify 3rd party personal data handling -highlighting special categories of personal data ✓ Conduct risk analysis - severity/probability model ✓ Update 3rd party contracts to ensure compliance to your company privacy program/GDPR ✓ Consider Supplier GDPR compliance attestations ✓ Vet new suppliers - walk away if not GDPR compliant! Immediate ▪ Create supplier pre-selection due diligence program ▪ Ensure contract templates are valid and up to date ▪ Develop supplier assurance program (assessments/audits) ▪ Closed loop corrective action ▪ Internal awareness/alignment across the organization ▪ Ensure demonstrable intent in relation to supplier program Futureplans GDPR – What do I need to do? What constitutes “sufficient guarantee” and how can this be measured?
  • 12. VEREGO: Your Partner in Assessing Third Party Risk - Due Diligence Our Platform We Assess We Review ▪ Online Supplier Reporting Platform ▪ Transparency for both Suppliers and Buyers ▪ Immediate communication and information exchange ▪ Reporting Capabilities contained within Platform ▪ Demonstrates Due Diligence ▪ Option for response Review by Independent 3rd Party Streamlined Supplier Assessments Ongoing Excellence in Data Protection Framework for Ongoing Management ▪ Standardized Questionnaire available or optional customized buyer GDPR Assessment ▪ Assessment Report on Performance and Risk
  • 13. Compliance dashboard The compliance dashboard enables the Buyer to track Suppliers as they register and publish GDPR information through SupplierPortal. All statistics are dependent on the chosen settings, meaning the compliance status of your suppliers can be analyzed and reported at anytime.
  • 14. Questionnaire analysis (option 2) The questionnaire analysis dashboard enables the Buyers to track the completion rate of all the questionnaires, including GDPR. The flag status shows if suppliers have triggered risk flags in any of the questionnaires. By clicking on individual questionnaires, Buyers can see the status of each supplier and if any flags have been raised.
  • 15. View supplier GDPR responses Each supplier profile contains multiple tabs of information for that supplier. GDPR responses can be reviewed and scored, and supporting documents downloaded.
  • 16. Risk flags Flags are set for high risk GDPR non-compliance issues. When a supplier publishes their response, users are alerted if any flags have been raised.
  • 17. Performance scorecards Through the GDPR scorecard a suppliers performance can be calculated in relation to other suppliers.
  • 18. GDPR Audit – Due Diligence to identify GAP GDPR data audits provided standardised review of all supplier responses. PDF versions of audits are available for distribution, and a database of all historical audits is held in the system. If required, third parties can be given access to designated suppliers for more detailed auditing/review.
  • 19. DCU Alpha Campus Old Finglas Rd, Glasnevin Dublin 11 Phone: +353 1 297 3390 Web: www.clearstreamsolutions.ie brian@clearstreamsolutions.ie