SlideShare a Scribd company logo
1 of 9
Preparing for the
EU Data Protection Regulation
(GDPR)
www.oyster-ims.com
April 2016
20 April 2016 Preparing for the EU GDPR
On April 14 2016, the European Union adopted the General Data
Protection Regulation (GDPR) after four years of negotiation
It will come into force in April 2018 - there are two components to the
new law:
The General Data Protection Regulation (GDPR) which is
designed to give EU citizens better control of their personal data
Data Protection Directive which covers how personal data is used
by police in the EU
Preparing for the EU GDPR – What is it?
20 April 2016 Preparing for the EU GDPR
Under the new rules:
Individuals will have more information on (and control over) how
their personal data is processed - data protection must be "by
default" and "by design" for products and services and include
adequate “affirmative consent”
Personal data will be portable, so that it can be moved more
easily between different organisations
The so-called "right to be forgotten“ is clarified under the GDPR
Preparing for the EU GDPR – What’s new?
20 April 2016 Preparing for the EU GDPR
Also:
Companies and organisations will have a greater level of
accountability including the obligation to inform national
supervisory bodies of serious data breaches so that appropriate
remediation measures can be taken
The new rules will be backed up by much stronger enforcement:
data protection authorities will be able to fine companies that do
not comply up to 4 percent of global annual turnover
Preparing for the EU GDPR – What’s new?
20 April 2016 Preparing for the EU GDPR
In order to be ready for the new regulations you first need to
understand what personal data you have, how you use personal data,
where and how personal data is stored and how personal data is
transferred internally and externally including cross-border transfers
There are three main locations for personal data:
Paper: local, on-site and off-site repositories
Structured Data: line of business systems and other database
applications
Unstructured Data: file share, email systems, document repositories
Preparing for the EU GDPR – Where to Start
20 April 2016 Preparing for the EU GDPR
In order to get an accurate picture you need to carry out a data
protection audit which should consist of:
Creation of a custom personal data classification scheme for the
organisation
A review of the organisation’s data protection landscape including
the policies, procedures and controls currently in place
A business engagement, prioritised using a risk-based approach, to
understand all interactions with personal data
A review of all locations, supported by file analytics software, to
discover personal data and bring it under appropriate management
Data Protection Audit
20 April 2016 Preparing for the EU GDPR
The data protection audit will deliver:
Personal data “data map” showing locations of personal data and
identifying high risk areas
Fully documented personal data flows showing movement of
personal data
Remediation programme to deliver compliance with GDPR
Audit Outcomes and Compliance
20 April 2016 Preparing for the EU GDPR
Data Protection Audit Case Study
20 April 2016 Preparing for the EU GDPR
The Client
A global insurer and reinsurer
Japanese owned with European
headquarters in Switzerland
Japanese parent has c.$85 billion
assets
Underwrites a diversified portfolio of
specialty lines business from its
operations at Lloyd's and globally
Significant growth over the last twelve
years through a mix of organic
expansion and acquisition and is one of
the top 10 insurers in the Lloyd's
insurance market, writing premiums in
excess of £1 billion
The Project
Personal data analysis and remediation
as part of a full Information Governance
Programme
Three levels of personal data defined –
Sensitive (Type A); Core (B); Contact
and Organisational (C)
Oyster IMS carried out Global Data
Protection and Privacy Audit to report on
creation, capture, storage, management
and transfer of type A and B personal
data
Automated file analysis tool to search
for content across 50Tb of data equating
to 30 million files
The Results
> 250,000 files identified
containing personal data from
defined categories
Split between personal data
found in locations identified by
business during audit and
elsewhere
74%
26%
Type A Personal Data
Found in Expected
Found Elsewhere
For more information contact:
info@oyster-ims.com
0207 199 0620
www.oyster-ims.com
Preparing for the EU GDPR20 April 2016

More Related Content

Recently uploaded

Mental Health Issues of Graduate Students
Mental Health Issues of Graduate StudentsMental Health Issues of Graduate Students
Mental Health Issues of Graduate Students
vineshkumarsajnani12
 
Obat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di Depok
Obat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di DepokObat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di Depok
Obat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di Depok
Obat Aborsi Jakarta Wa 085176963835 Apotek Jual Obat Cytotec Di Jakarta
 
Obat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di Surabaya
Obat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di SurabayaObat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di Surabaya
Obat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di Surabaya
Obat Aborsi Jakarta Wa 085176963835 Apotek Jual Obat Cytotec Di Jakarta
 
Contact +971581248768 for 100% original and safe abortion pills available for...
Contact +971581248768 for 100% original and safe abortion pills available for...Contact +971581248768 for 100% original and safe abortion pills available for...
Contact +971581248768 for 100% original and safe abortion pills available for...
DUBAI (+971)581248768 BUY ABORTION PILLS IN ABU dhabi...Qatar
 
obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...
obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...
obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...
yulianti213969
 
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
nafizanafzal
 
Obat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di Pasuruan
Obat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di PasuruanObat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di Pasuruan
Obat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di Pasuruan
Obat Aborsi Jakarta Wa 085176963835 Apotek Jual Obat Cytotec Di Jakarta
 
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in PakistanChallenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
vineshkumarsajnani12
 

Recently uploaded (20)

Mental Health Issues of Graduate Students
Mental Health Issues of Graduate StudentsMental Health Issues of Graduate Students
Mental Health Issues of Graduate Students
 
Obat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di Depok
Obat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di DepokObat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di Depok
Obat Aborsi Depok 0851\7696\3835 Jual Obat Cytotec Di Depok
 
Obat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di Surabaya
Obat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di SurabayaObat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di Surabaya
Obat Aborsi Surabaya 0851\7696\3835 Jual Obat Cytotec Di Surabaya
 
Contact +971581248768 for 100% original and safe abortion pills available for...
Contact +971581248768 for 100% original and safe abortion pills available for...Contact +971581248768 for 100% original and safe abortion pills available for...
Contact +971581248768 for 100% original and safe abortion pills available for...
 
Unlocking Growth The Power of Outsourcing for CPA Firms
Unlocking Growth The Power of Outsourcing for CPA FirmsUnlocking Growth The Power of Outsourcing for CPA Firms
Unlocking Growth The Power of Outsourcing for CPA Firms
 
The Vietnam Believer Newsletter_May 13th, 2024_ENVol. 007.pdf
The Vietnam Believer Newsletter_May 13th, 2024_ENVol. 007.pdfThe Vietnam Believer Newsletter_May 13th, 2024_ENVol. 007.pdf
The Vietnam Believer Newsletter_May 13th, 2024_ENVol. 007.pdf
 
First Time Home Buyer's Guide - KM Realty Group LLC
First Time Home Buyer's Guide - KM Realty Group LLCFirst Time Home Buyer's Guide - KM Realty Group LLC
First Time Home Buyer's Guide - KM Realty Group LLC
 
obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...
obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...
obat aborsi bandung wa 081336238223 jual obat aborsi cytotec asli di bandung9...
 
WAM Corporate Presentation May 2024_w.pdf
WAM Corporate Presentation May 2024_w.pdfWAM Corporate Presentation May 2024_w.pdf
WAM Corporate Presentation May 2024_w.pdf
 
How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...
How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...
How Bookkeeping helps you in Cost Saving, Tax Saving and Smooth Business Runn...
 
Pixar Case Analysis.....................
Pixar Case Analysis.....................Pixar Case Analysis.....................
Pixar Case Analysis.....................
 
A DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptx
A DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptxA DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptx
A DAY IN LIFE OF A NEGOTIATOR By Pondicherry University MBA Students.pptx
 
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![©  ر
00971508021841 حبوب الإجهاض في دبي | أبوظبي | الشارقة | السطوة |❇ ❈ ((![© ر
 
Chapter 2 Organization Structure of a Treasury
Chapter 2 Organization Structure of a TreasuryChapter 2 Organization Structure of a Treasury
Chapter 2 Organization Structure of a Treasury
 
Obat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di Pasuruan
Obat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di PasuruanObat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di Pasuruan
Obat Aborsi Pasuruan 0851\7696\3835 Jual Obat Cytotec Di Pasuruan
 
Beyond Numbers A Holistic Approach to Forensic Accounting
Beyond Numbers A Holistic Approach to Forensic AccountingBeyond Numbers A Holistic Approach to Forensic Accounting
Beyond Numbers A Holistic Approach to Forensic Accounting
 
10 Easiest Ways To Buy Verified TransferWise Accounts
10 Easiest Ways To Buy Verified TransferWise Accounts10 Easiest Ways To Buy Verified TransferWise Accounts
10 Easiest Ways To Buy Verified TransferWise Accounts
 
What are the differences between an international company, a global company, ...
What are the differences between an international company, a global company, ...What are the differences between an international company, a global company, ...
What are the differences between an international company, a global company, ...
 
The Art of Decision-Making: Navigating Complexity and Uncertainty
The Art of Decision-Making: Navigating Complexity and UncertaintyThe Art of Decision-Making: Navigating Complexity and Uncertainty
The Art of Decision-Making: Navigating Complexity and Uncertainty
 
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in PakistanChallenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
Challenges and Opportunities: A Qualitative Study on Tax Compliance in Pakistan
 

Featured

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 

Preparing for GDPR - Oyster IMS

  • 1. Preparing for the EU Data Protection Regulation (GDPR) www.oyster-ims.com April 2016 20 April 2016 Preparing for the EU GDPR
  • 2. On April 14 2016, the European Union adopted the General Data Protection Regulation (GDPR) after four years of negotiation It will come into force in April 2018 - there are two components to the new law: The General Data Protection Regulation (GDPR) which is designed to give EU citizens better control of their personal data Data Protection Directive which covers how personal data is used by police in the EU Preparing for the EU GDPR – What is it? 20 April 2016 Preparing for the EU GDPR
  • 3. Under the new rules: Individuals will have more information on (and control over) how their personal data is processed - data protection must be "by default" and "by design" for products and services and include adequate “affirmative consent” Personal data will be portable, so that it can be moved more easily between different organisations The so-called "right to be forgotten“ is clarified under the GDPR Preparing for the EU GDPR – What’s new? 20 April 2016 Preparing for the EU GDPR
  • 4. Also: Companies and organisations will have a greater level of accountability including the obligation to inform national supervisory bodies of serious data breaches so that appropriate remediation measures can be taken The new rules will be backed up by much stronger enforcement: data protection authorities will be able to fine companies that do not comply up to 4 percent of global annual turnover Preparing for the EU GDPR – What’s new? 20 April 2016 Preparing for the EU GDPR
  • 5. In order to be ready for the new regulations you first need to understand what personal data you have, how you use personal data, where and how personal data is stored and how personal data is transferred internally and externally including cross-border transfers There are three main locations for personal data: Paper: local, on-site and off-site repositories Structured Data: line of business systems and other database applications Unstructured Data: file share, email systems, document repositories Preparing for the EU GDPR – Where to Start 20 April 2016 Preparing for the EU GDPR
  • 6. In order to get an accurate picture you need to carry out a data protection audit which should consist of: Creation of a custom personal data classification scheme for the organisation A review of the organisation’s data protection landscape including the policies, procedures and controls currently in place A business engagement, prioritised using a risk-based approach, to understand all interactions with personal data A review of all locations, supported by file analytics software, to discover personal data and bring it under appropriate management Data Protection Audit 20 April 2016 Preparing for the EU GDPR
  • 7. The data protection audit will deliver: Personal data “data map” showing locations of personal data and identifying high risk areas Fully documented personal data flows showing movement of personal data Remediation programme to deliver compliance with GDPR Audit Outcomes and Compliance 20 April 2016 Preparing for the EU GDPR
  • 8. Data Protection Audit Case Study 20 April 2016 Preparing for the EU GDPR The Client A global insurer and reinsurer Japanese owned with European headquarters in Switzerland Japanese parent has c.$85 billion assets Underwrites a diversified portfolio of specialty lines business from its operations at Lloyd's and globally Significant growth over the last twelve years through a mix of organic expansion and acquisition and is one of the top 10 insurers in the Lloyd's insurance market, writing premiums in excess of £1 billion The Project Personal data analysis and remediation as part of a full Information Governance Programme Three levels of personal data defined – Sensitive (Type A); Core (B); Contact and Organisational (C) Oyster IMS carried out Global Data Protection and Privacy Audit to report on creation, capture, storage, management and transfer of type A and B personal data Automated file analysis tool to search for content across 50Tb of data equating to 30 million files The Results > 250,000 files identified containing personal data from defined categories Split between personal data found in locations identified by business during audit and elsewhere 74% 26% Type A Personal Data Found in Expected Found Elsewhere
  • 9. For more information contact: info@oyster-ims.com 0207 199 0620 www.oyster-ims.com Preparing for the EU GDPR20 April 2016