SlideShare ist ein Scribd-Unternehmen logo
1 von 14
GDPR Overview
Gydeline – October 2017
Where are we?
• Comes into force May 2018
• Addresses personal ‘information’ & ‘data’ and how it is used in the
21st century
• Gives new rights to data subjects
• Applies to both ‘controllers’ and ‘processors’
• Applies to organisations based in the EU and those that sell
goods and services into the EU or in EU currencies/languages.
Personal data
• Name
• ID numbers
• Location data
• Online identifiers (IP address/cookies etc)
• Physical, genetic, mental, economic, social or cultural identifiers
. . . . .of a natural person
. . . . .stored in computer or paper based filing systems
Special categories of data (sensitive)
• Racial or ethnic origin
• Political opinions
• Religious or philosophical beliefs
• Trade union membership
• Genetic data
• Under 16s
• Biometric data for the purpose of uniquely identifying a natural person
• Health data or data concerning a natural person's sex life or sexual
orientation
Basic GDPR Principles
• Fair, lawful and transparent processing
• Correct, stated purpose
• Data minimisation
• Accurate and up to date
• Kept no longer than necessary
• Secure
• Accountable. . . . . “the controller shall be responsible
for, and be able to demonstrate,
compliance with the principles”
How do we do this GDPR thing?
Identify a legal basis:
• Consent
• Performance of a contract
• Necessary for compliance
• Protection of vital interests (subject of another person)
• Public Interest/Official authority vested in the controller
• Legitimate interests
If using consent:
• Clear, affirmative action (no silence or pre-ticking)
• Auditable – record of consent needed
• Can be withdrawn
• Not a pre-condition of service
• Extensive information to be provided
• Special categories require additional conditions
• Consent can be explicit or implicit (i.e. visiting a Doctor) but must
be unambiguous
Rights of the data subject
• The right to be informed (Privacy notice)
• The right of access
• The right to rectification
• The right to erasure
• The right to restrict processing
• The right to data portability
• The right to object
• The right not to be subject to automated decision making and
profiling
Implications of GDPR
Governance considerations
• Processing records
• Consent records
• Data Protection impact assessments
• DPO requirements
• Information provision (Privacy notice/policy)
• Data policies (retention, destruction, backup etc etc)
• Security policies (access, passwords, etc etc)
• Regular review of measures/governance
DPO
• Required if:
• Public Authority
• Large scale processing (scope and schedule)
• Special categories
• More than 250FTE
• Qualifications
• Audit
• IT Security
• EU data protection law
• Company knowledge
• etc
Reporting
• Demonstrating compliance with GDPR
• Notify supervisory authority about unmitigated risks
• Breach
• Contacts (DPO, Processor etc)
• Demonstrating accountability
• DP Policies
• Staff training
• Auditing and processing activities
• Data minimisation
• Pseudonymising
• Security features (Identity and Access, Encryption, Classification, Rights, masking etc.)
• Data Protection Impact Assessments
What does Gydeline do?
• Checks for compliance against everything mentioned above
• Enables proof of accountability
• Changes as the regulation changes
• Identifies specific actions
• Makes GDPR simpler to understand
End
www.gydeline.com
hello@gydeline.com

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
 
General Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data TransfersGeneral Data Protection Regulation (GDPR) - Cross-Border Data Transfers
General Data Protection Regulation (GDPR) - Cross-Border Data Transfers
 
DCH Data Protection Training Presentation
DCH Data Protection Training PresentationDCH Data Protection Training Presentation
DCH Data Protection Training Presentation
 
Urgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data PribadiUrgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data Pribadi
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
KSA PDPL - Personal Data Protection Law.pdf
KSA PDPL - Personal Data Protection Law.pdfKSA PDPL - Personal Data Protection Law.pdf
KSA PDPL - Personal Data Protection Law.pdf
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theft
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
GDPR
GDPRGDPR
GDPR
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Data protection regulation
Data protection regulationData protection regulation
Data protection regulation
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
LGPD | CICLO DE PALESTRAS
LGPD | CICLO DE PALESTRASLGPD | CICLO DE PALESTRAS
LGPD | CICLO DE PALESTRAS
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
GDPR vs US Regulations: Their differences and Commonalities with ISO/IEC 27701
 

Ähnlich wie Simple GDPR Overview

LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
TimBee1
 

Ähnlich wie Simple GDPR Overview (20)

GDPR Practicalities - The Data Shed
GDPR Practicalities - The Data ShedGDPR Practicalities - The Data Shed
GDPR Practicalities - The Data Shed
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
General-Data-Protection-Regulation-GDPR.pptx
General-Data-Protection-Regulation-GDPR.pptxGeneral-Data-Protection-Regulation-GDPR.pptx
General-Data-Protection-Regulation-GDPR.pptx
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Data Protection and IDEA
Data Protection and IDEAData Protection and IDEA
Data Protection and IDEA
 
Media_644046_smxx (1).pptx
Media_644046_smxx (1).pptxMedia_644046_smxx (1).pptx
Media_644046_smxx (1).pptx
 
Data Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPRData Protection: Transitioning to the GDPR
Data Protection: Transitioning to the GDPR
 
Data Protection GDPR Basics
Data Protection GDPR BasicsData Protection GDPR Basics
Data Protection GDPR Basics
 
Gdpr for business full
Gdpr for business fullGdpr for business full
Gdpr for business full
 
Gdpr
GdprGdpr
Gdpr
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Constraintsand challenges
Constraintsand challengesConstraintsand challenges
Constraintsand challenges
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR Privacy Introduction
GDPR Privacy IntroductionGDPR Privacy Introduction
GDPR Privacy Introduction
 
LW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptxLW GDPR and Cyber Security.pptx
LW GDPR and Cyber Security.pptx
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 

Kürzlich hochgeladen

Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for Viewing
Nauman Safdar
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
allensay1
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
daisycvs
 

Kürzlich hochgeladen (20)

Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for Viewing
 
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NSCROSS CULTURAL NEGOTIATION BY PANMISEM NS
CROSS CULTURAL NEGOTIATION BY PANMISEM NS
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service AvailableNashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
 
New 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateNew 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck Template
 
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur DubaiUAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
UAE Bur Dubai Call Girls ☏ 0564401582 Call Girl in Bur Dubai
 
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 
HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024HomeRoots Pitch Deck | Investor Insights | April 2024
HomeRoots Pitch Deck | Investor Insights | April 2024
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Buy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail AccountsBuy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail Accounts
 
JAJPUR CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN JAJPUR ESCORTS
JAJPUR CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN JAJPUR  ESCORTSJAJPUR CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN JAJPUR  ESCORTS
JAJPUR CALL GIRL ❤ 82729*64427❤ CALL GIRLS IN JAJPUR ESCORTS
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
 
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGBerhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 

Simple GDPR Overview

  • 2. Where are we? • Comes into force May 2018 • Addresses personal ‘information’ & ‘data’ and how it is used in the 21st century • Gives new rights to data subjects • Applies to both ‘controllers’ and ‘processors’ • Applies to organisations based in the EU and those that sell goods and services into the EU or in EU currencies/languages.
  • 3. Personal data • Name • ID numbers • Location data • Online identifiers (IP address/cookies etc) • Physical, genetic, mental, economic, social or cultural identifiers . . . . .of a natural person . . . . .stored in computer or paper based filing systems
  • 4. Special categories of data (sensitive) • Racial or ethnic origin • Political opinions • Religious or philosophical beliefs • Trade union membership • Genetic data • Under 16s • Biometric data for the purpose of uniquely identifying a natural person • Health data or data concerning a natural person's sex life or sexual orientation
  • 5. Basic GDPR Principles • Fair, lawful and transparent processing • Correct, stated purpose • Data minimisation • Accurate and up to date • Kept no longer than necessary • Secure • Accountable. . . . . “the controller shall be responsible for, and be able to demonstrate, compliance with the principles”
  • 6. How do we do this GDPR thing? Identify a legal basis: • Consent • Performance of a contract • Necessary for compliance • Protection of vital interests (subject of another person) • Public Interest/Official authority vested in the controller • Legitimate interests
  • 7. If using consent: • Clear, affirmative action (no silence or pre-ticking) • Auditable – record of consent needed • Can be withdrawn • Not a pre-condition of service • Extensive information to be provided • Special categories require additional conditions • Consent can be explicit or implicit (i.e. visiting a Doctor) but must be unambiguous
  • 8. Rights of the data subject • The right to be informed (Privacy notice) • The right of access • The right to rectification • The right to erasure • The right to restrict processing • The right to data portability • The right to object • The right not to be subject to automated decision making and profiling
  • 10. Governance considerations • Processing records • Consent records • Data Protection impact assessments • DPO requirements • Information provision (Privacy notice/policy) • Data policies (retention, destruction, backup etc etc) • Security policies (access, passwords, etc etc) • Regular review of measures/governance
  • 11. DPO • Required if: • Public Authority • Large scale processing (scope and schedule) • Special categories • More than 250FTE • Qualifications • Audit • IT Security • EU data protection law • Company knowledge • etc
  • 12. Reporting • Demonstrating compliance with GDPR • Notify supervisory authority about unmitigated risks • Breach • Contacts (DPO, Processor etc) • Demonstrating accountability • DP Policies • Staff training • Auditing and processing activities • Data minimisation • Pseudonymising • Security features (Identity and Access, Encryption, Classification, Rights, masking etc.) • Data Protection Impact Assessments
  • 13. What does Gydeline do? • Checks for compliance against everything mentioned above • Enables proof of accountability • Changes as the regulation changes • Identifies specific actions • Makes GDPR simpler to understand

Hinweis der Redaktion

  1. This presentation gives a brief overview of the major points contained in the GDPR, the Gydeline approach and some next steps to think about. It should be noted that the website of the Information Commissioners Office is a great resource and should be considered the primary source for organisations in the UK. Gydeline takes the GDPR regulation and guidance from the ICO and gives output specific to a single organisation.
  2. Here are some key overview points and context to consider when thinking about GDPR.
  3. In order to avoid confusion, the GDPR applies to personal data. Personal data is one of the following. Personal data relates to a natural person rather than any organisation. GDPR applies to the data irrespective of whether it is stored on electronic, paper or any other type of filing system. Filing implies that the data is structured and searchable in some way as opposed to random and unsearchable.
  4. Some types of personal data attract special consideration under the GDPR and so are worth noting.
  5. The GDPR enshrines some basic data protection principles. It also requires that organisations are able to demonstrate their compliance with the GDPR – the Gydeline software is one way of demonstrating an organisations compliance position.
  6. The first step when looking at GDPR should be to understand the legal basis upon which you are processing personal data. Consent is one method which is getting a lot of attention, however contracts will negate the need for consent in many instances as will vital and legitimate interests. By understanding your legal basis, an organisation may free itself from some requirements under the GDPR – or at least understand more clearly the scope which applies to them.
  7. If consent is used as the basis of processing it must follow the following rules:
  8. The GDPR gives rights to the data subject. Organisations should be aware of, and have processes, to support all these rights.
  9. This slide seeks to give a simple, easy to understand breakdown of the major areas of action organisations need to take. In terms of implementation, if an organisation does everything on this slide they will most likely be 99% compliant with the GDPR.
  10. There are many overriding governance considerations within GDPR. These need to be available and documented should the supervisory authority (ICO in the UK) request information.
  11. Finding the correct Data Protection Officer, if required, can be challenging as there are few individuals with the requisite IT AND legal skills and experience.
  12. Building on the governance considerations there are specific reporting requirements under the GDPR which need to be met.
  13. A basic overview of the Gydeline software. For more information go to https://www.gydeline.com or email hello@gydeline.com