SlideShare a Scribd company logo
1 of 22
7 things you should know
about EU GDPR
Shadi A. Razak
7th October 2016
Introduction
• Shadi A. Razak
– Chief Technology Officer
– Head of Compliance and Cyber Security Solutions
– 15 international experience in:
• Cyber security,
• Information compliance
• Business digitalisation
– Private and public Sector
– SMEs and International blue chip corporations
Introduction
We do that by providing innovative
cyber security and information
compliance solutions that
encompass people, processes and
technology, enabling organisations
to become more resilient and
effective against threats.
We help organisations improve their
compliance & security posture.
Introduction
Fraud Detection
CyNation’s offers the most powerful
yet easy to use analysis tools for
detecting and preventing invisible
internal fraud, external theft and poor
procedural compliance.
Ubiquitous Monitoring
Combining an innovative object persistent database, advanced ubiquitous
data collector with data analytics and high visualisation to proactively
monitor multiple data types in one configurable system.
Secure Communications
CyNation’s Secure Communication
Platform (SCP) protects confidential
information flows between employees
and external parties through a secure
communications application that looks
like email and is as easy to use as the
popular instant messaging clients.
Cyber Security Literacy
Tailor-made workshops and training
sessions for Boards, C-suite
executives & management from cyber
security awareness to cyber crisis
incident response planning and
simulation.
GRC (Compliance Management)
Combining human expertise with advanced
data monitoring, data analytics &
visualisation to proactively manage and
comply with technical, operational, financial
and legal standards and regulations.
Comprehensive Threat Insight
Combining advanced solutions of data
analytics and visualisation to proactively
manage and avert threats.
Ongoing Risk Assessment
Combining business risk
assessments, advanced vulnerability
assessments and penetration testing
with data analytics to proactively
assess and manage cyber risk.
Agenda
• The landscape
• EU GDPR
– Structure
– Aim
– Benefits
– Consequences
– Data Security
• 7 things you should know
• 7 Steps to be ready
The landscape
$
V.S
Different
legal system
across the
world
Personal
data is
valuable
Contrast
between
Europe & US
legislation
The landscape
Source: UNCTD, 2016
EU GDPR
European Union General Data Protection Regulation
General Provisions (Articles 1-4)
Principles (Articles 5-11)
Rights of Data Subjects: 5 Sections (Articles 12-23)
Controller and Processors: 5 Section (Articles 24-43)
Transfer of Personal Data (Articles 44-50)
Independent Supervisory Authorities (Articles 51-59)
Cooperation and Consistency (Articles 60-76)
Remedies, Liabilities and Penalties (Articles 77-84)
Processing Situation Provisions (Article 85-91)
Delegation and Implementation Act (Article 92&93)
Final Provisions (Articles 94-99)
1
2
3
4
5
6
7
8
9
10
11
The core of
the regulation
How supervisory
authorities at the
EU are going to
enforce the
regulation
EU GDPR
ConsequencesBenefits
Aim
EU GDPR - Aim
• One Regulation
• Stronger enforcement body
• Data Protection Impact Assessment (DPIA)
• Include international suppliers in regulation
scope
• Diminish distinction between processor and
controller
EU GDPR - Benefits
• For business:
– One market : one law
– One stop shop
– Same rules for all companies
– No general registration requirement
EU GDPR - Benefits
• For customers / citizens:
– Better data security
– Better control over your personal data:
• Mandatory consent
• Right to be forgotten
• Right to object to profiling
• Better subject access request (SAR) regime
EU GDPR - Consequences
• Fine of €10million or 2% of global turnover, whichever is
greater:
ꟷ 8: Child’s consent
ꟷ 11: Processing not requiring
identification
ꟷ 25: Data protection by design and by
default
ꟷ 26 - 30: Processing
ꟷ 31: Cooperation with the supervisory
authority
ꟷ 32: Data security
ꟷ 33: Notification of breaches to
supervisory authority
ꟷ 34: Communication of breaches to
data subjects
ꟷ 35: Data protection impact
assessment
ꟷ 36: Prior consultation
ꟷ 37 -39: DPOs
ꟷ 41(4): Monitoring approved
codes of conduct
ꟷ 42: Certification
ꟷ 43: Certification bodies
EU GDPR - Consequences
• Fine of €20million or 4% of global turnover, whichever is
greater:
– 5: Principles relating to the processing of personal data
– 6: Lawfulness of processing
– 7: Conditions for consent
– 9: Processing special categories of personal data (i.e. sensitive
personal data)
– 12 - 22: Data subject rights
– 44 - 49: Transfers to third countries
– 58(1): Requirement to provide access to supervisory authority
– 58(2): Orders/limitations on processing or the suspension of data
flows
EU GDPR - Consequences
Audit failure
Fines &
criminal
charges
Financial loss
Loss of data
confidentiality,
integrity
and/or
availability
Violation of
employee
privacy
Loss of
customer
Trust
Loss of brand
reputation
Loss of
market share
Damaged
reputation
Legal
exposure
CEO CFO/COO CIO CHRO CMO
Greater Reputation
Risk
EU GDPR – Data security
• Chapter 4:
– 4 Key articles:
• Section 2: Security of personal data
– Article 32: Security of Processing
– Article 33: Notification of personal data breaches to the supervisory
authority
– Article 34: Communication of personal data breaches to the data
subjects
• Section 3: Data Protection Impact Assessment and Prior
Consultation
– Article 35: Data protection impact assessment
EU GDPR – Data security
Organisation must Organisation will
• greatly reduce the
likelihood of being fined
• will not need to notify
affected data subjects of
the breach
• Implement appropriate security
measures to protect personal
data
• Have a clear data protection
policy
• Have named a data protection
officer
7 Thing you should know
EU GDPR is already a reality
It is all about protecting the fundamental rights of natural
person
It applies to every organisation and every type of data
Consent Rules
Accountability and transparency are the organisation
responsibility
Data Protection Officer is needed
Encryption is not the answer
1
2
3
4
5
6
7
7 steps to get ready
1
• Audit your data
2
• Identify who is responsible for this data
3
• Design and implement appropriate measure to protect this data
4
• Develop processes to deal with breaches/incidents
5
• Designate a Data protection Officer (DPO) and supporting team
6
• Understand who is data you are controlling and/or processing
7
• Develop culture of Privacy by design wide across the organisation
7 steps to get ready
1
• Audit your data
2
• Identify who is responsible for this data
3
• Design and implement appropriate measure to protect this data
4
• Develop processes to deal with breaches/incidents
5
• Designate a Data protection Officer (DPO) and supporting team
6
• Understand who is data you are controlling and/or processing
7
• Develop culture of Privacy by design wide across the organisation
EU GDPR Readiness
• Get your organisation EU GDPR Readiness report -
December 2016 (contact@cynation.com)
© Copyright CyNation Limited 2016. All rights reserved. Without the express prior written consent of the CyNation, the presentation and any information contained within it may not be
(i) reproduced (in whole or in part), (ii) copied at any time, (iii)used for any purpose other than your evaluation of the company or (iv) provided to any other person, except your
employees, and advisors with a need to know who are advised of the confidentiality of the information. The information contained in these materials is provided for informational
purposes only, and is provided as is without warranty of any kind, express or implied. CyNation shall not be responsible for any damages arising out of the use of, or otherwise related
to, these materials. Nothing contained in these materials is intended to, nor shall have the effect of, creating any warranties or representations from CyNation or its suppliers or
licensors, or altering the terms and conditions of the applicable license agreement governing the use of CyNation solutions and services. Product release dates and / or capabilities
referenced in these materials may change at any time at CyNation’s sole discretion based on market opportunities or other factors, and are not intended to be a commitment to future
product or feature availability in any way.
We would be delighted to talk to you:
Shadi A. Razak
shadi.razak@cynation.com
T: +44(0)7768 686638

More Related Content

What's hot

Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPRPaul O'Carroll
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksIT Governance Ltd
 
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...IT Governance Ltd
 
GDPR in practice
GDPR in practiceGDPR in practice
GDPR in practiceZoneFox
 
Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...IT Governance Ltd
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]TrustArc
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance Tom Haynes
 
SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution Google
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...Ardoq
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
1211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-161211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-16jbauerofprivacy
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketingSpotler
 
Are you preparing for GDPR?
Are you preparing for GDPR?Are you preparing for GDPR?
Are you preparing for GDPR?Chris Bullock
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...IT Governance Ltd
 
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Codemotion
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing MindsetNetworkIQ
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality Susan Moran
 
Digital Forensics 101 – How is it used to protect an Organization’s Data?
Digital Forensics 101 – How is it used to protect an Organization’s Data?Digital Forensics 101 – How is it used to protect an Organization’s Data?
Digital Forensics 101 – How is it used to protect an Organization’s Data?PECB
 

What's hot (20)

Teradata's approach to addressing GDPR
Teradata's approach to addressing GDPRTeradata's approach to addressing GDPR
Teradata's approach to addressing GDPR
 
GDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risksGDPR compliance and information security: Reducing data breach risks
GDPR compliance and information security: Reducing data breach risks
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
 
GDPR in practice
GDPR in practiceGDPR in practice
GDPR in practice
 
Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...Addressing penetration testing and vulnerabilities, and adding verification m...
Addressing penetration testing and vulnerabilities, and adding verification m...
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance EU GDPR - 12 Steps To Compliance
EU GDPR - 12 Steps To Compliance
 
SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution SureSkills GDPR - Discover the Smart Solution
SureSkills GDPR - Discover the Smart Solution
 
GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...GDPR From the Trenches - Real-world examples of how companies are approaching...
GDPR From the Trenches - Real-world examples of how companies are approaching...
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
1211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-161211000-792-2-Promontory - Data Mapping Slides 06-06-16
1211000-792-2-Promontory - Data Mapping Slides 06-06-16
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
 
Are you preparing for GDPR?
Are you preparing for GDPR?Are you preparing for GDPR?
Are you preparing for GDPR?
 
Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...Legal obligations and responsibilities of data processors and controllers und...
Legal obligations and responsibilities of data processors and controllers und...
 
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality GDPR – The Practicalities of a New Reality
GDPR – The Practicalities of a New Reality
 
Digital Forensics 101 – How is it used to protect an Organization’s Data?
Digital Forensics 101 – How is it used to protect an Organization’s Data?Digital Forensics 101 – How is it used to protect an Organization’s Data?
Digital Forensics 101 – How is it used to protect an Organization’s Data?
 

Viewers also liked

GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?DATUM LLC
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPRTripwire
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
CyNation - Securing Communication in the Automotive World
CyNation - Securing Communication in the Automotive WorldCyNation - Securing Communication in the Automotive World
CyNation - Securing Communication in the Automotive WorldIryna Chekanava
 
TCF Nieuwsbrief Bovib Modelovereenkomst
TCF Nieuwsbrief  Bovib ModelovereenkomstTCF Nieuwsbrief  Bovib Modelovereenkomst
TCF Nieuwsbrief Bovib ModelovereenkomstRoy Kolmschot ✔
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
Sox Compliance Presentation
Sox Compliance PresentationSox Compliance Presentation
Sox Compliance PresentationSkye Rogers
 
Command Query Responsibility Segregation
Command Query Responsibility SegregationCommand Query Responsibility Segregation
Command Query Responsibility SegregationSkills Matter
 
S O X In Telecom Industry
S O X In  Telecom  IndustryS O X In  Telecom  Industry
S O X In Telecom Industryravindra sharma
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersIT Governance Ltd
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
 
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?SAPinsider Events
 
2017 The CMR Agency AVG/ GDPR seminar
2017 The CMR Agency AVG/ GDPR seminar2017 The CMR Agency AVG/ GDPR seminar
2017 The CMR Agency AVG/ GDPR seminarThe CMR Agency
 
EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer IT Governance Ltd
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? Desynit
 
DevOps vs GDPR: How to Comply and Stay Agile
DevOps vs GDPR: How to Comply and Stay AgileDevOps vs GDPR: How to Comply and Stay Agile
DevOps vs GDPR: How to Comply and Stay AgileBen Saunders
 

Viewers also liked (20)

GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?GDPR: Is Your Organization Ready for the General Data Protection Regulation?
GDPR: Is Your Organization Ready for the General Data Protection Regulation?
 
An Essential Guide to EU GDPR
An Essential Guide to EU GDPRAn Essential Guide to EU GDPR
An Essential Guide to EU GDPR
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
CyNation - Securing Communication in the Automotive World
CyNation - Securing Communication in the Automotive WorldCyNation - Securing Communication in the Automotive World
CyNation - Securing Communication in the Automotive World
 
TCF Nieuwsbrief Bovib Modelovereenkomst
TCF Nieuwsbrief  Bovib ModelovereenkomstTCF Nieuwsbrief  Bovib Modelovereenkomst
TCF Nieuwsbrief Bovib Modelovereenkomst
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Ey segregation of_duties
Ey segregation of_dutiesEy segregation of_duties
Ey segregation of_duties
 
Sox Compliance Presentation
Sox Compliance PresentationSox Compliance Presentation
Sox Compliance Presentation
 
Command Query Responsibility Segregation
Command Query Responsibility SegregationCommand Query Responsibility Segregation
Command Query Responsibility Segregation
 
eTOM - Foundation
eTOM - FoundationeTOM - Foundation
eTOM - Foundation
 
S O X In Telecom Industry
S O X In  Telecom  IndustryS O X In  Telecom  Industry
S O X In Telecom Industry
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud Providers
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
Rethinking Segregation of Duties: Where Is Your Business Most Exposed?
 
2017 The CMR Agency AVG/ GDPR seminar
2017 The CMR Agency AVG/ GDPR seminar2017 The CMR Agency AVG/ GDPR seminar
2017 The CMR Agency AVG/ GDPR seminar
 
Gdpr compliance
Gdpr complianceGdpr compliance
Gdpr compliance
 
3GRC approach to GDPR V 0.1 www.3grc.co.uk
3GRC  approach to GDPR V 0.1 www.3grc.co.uk3GRC  approach to GDPR V 0.1 www.3grc.co.uk
3GRC approach to GDPR V 0.1 www.3grc.co.uk
 
EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer EU GDPR: The role of the data protection officer
EU GDPR: The role of the data protection officer
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me?
 
DevOps vs GDPR: How to Comply and Stay Agile
DevOps vs GDPR: How to Comply and Stay AgileDevOps vs GDPR: How to Comply and Stay Agile
DevOps vs GDPR: How to Comply and Stay Agile
 

Similar to CyNation: 7 Things You Should Know about EU GDPR

Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers Gary Dodson
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRMatt Stubbs
 
GDPR and ISO 27001 - how to be compliant
GDPR and ISO 27001 - how to be compliantGDPR and ISO 27001 - how to be compliant
GDPR and ISO 27001 - how to be compliantIlesh Dattani
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR ComplianceGabor Farkas
 
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) plan
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) planCWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) plan
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) planCapgemini
 
Automatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy StandardsAutomatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy Standardsautomatskicorporation
 
GDPR Part 2: Quest Relevance
GDPR Part 2: Quest RelevanceGDPR Part 2: Quest Relevance
GDPR Part 2: Quest RelevanceAdrian Dumitrescu
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowSymantec
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR & IBM i Security
GDPR & IBM i SecurityGDPR & IBM i Security
GDPR & IBM i SecurityPrecisely
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...Symantec
 
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...Symantec
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To ConsiderSymantec
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 

Similar to CyNation: 7 Things You Should Know about EU GDPR (20)

14.3.2018, Παρουσίαση Κώστα Γκρίτση στην εκδήλωση «Προστασία Προσωπικών Δεδομ...
14.3.2018, Παρουσίαση Κώστα Γκρίτση στην εκδήλωση «Προστασία Προσωπικών Δεδομ...14.3.2018, Παρουσίαση Κώστα Γκρίτση στην εκδήλωση «Προστασία Προσωπικών Δεδομ...
14.3.2018, Παρουσίαση Κώστα Γκρίτση στην εκδήλωση «Προστασία Προσωπικών Δεδομ...
 
The general data protection act overview
The general data protection act overviewThe general data protection act overview
The general data protection act overview
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPR
 
GDPR and ISO 27001 - how to be compliant
GDPR and ISO 27001 - how to be compliantGDPR and ISO 27001 - how to be compliant
GDPR and ISO 27001 - how to be compliant
 
5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance5 key steps for SMBs for reaching GDPR Compliance
5 key steps for SMBs for reaching GDPR Compliance
 
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) plan
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) planCWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) plan
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) plan
 
Automatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy StandardsAutomatski - The Internet of Things - Privacy Standards
Automatski - The Internet of Things - Privacy Standards
 
GDPR Part 2: Quest Relevance
GDPR Part 2: Quest RelevanceGDPR Part 2: Quest Relevance
GDPR Part 2: Quest Relevance
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t know
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR & IBM i Security
GDPR & IBM i SecurityGDPR & IBM i Security
GDPR & IBM i Security
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...
 
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...Symantec Webinar Part 4 of 6  GDPR Compliance, What NAM Organizations Need to...
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To Consider
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 

Recently uploaded

Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfKelechi48
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理ss
 
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.pptCorporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.pptRRR Chambers
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYJulian Scutts
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理Airst S
 
The Main Steps on Starting a Business in Spain
The Main Steps on Starting a Business in SpainThe Main Steps on Starting a Business in Spain
The Main Steps on Starting a Business in SpainBridgeWest.eu
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in LawNilendra Kumar
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.tanughoshal0
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...Finlaw Associates
 
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理A AA
 
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理F La
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdfSUSHMITAPOTHAL
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Nilendra Kumar
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理Airst S
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargainingbartzlawgroup1
 
一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理Airst S
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptxPamelaAbegailMonsant2
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书irst
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理Airst S
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringSteering Law
 

Recently uploaded (20)

Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.pptCorporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
Corporate Governance (Indian Scenario, Legal frame work in India ) - PPT.ppt
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
 
The Main Steps on Starting a Business in Spain
The Main Steps on Starting a Business in SpainThe Main Steps on Starting a Business in Spain
The Main Steps on Starting a Business in Spain
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in Law
 
ARTICLE 370 PDF about the indian constitution.
ARTICLE 370 PDF about the  indian constitution.ARTICLE 370 PDF about the  indian constitution.
ARTICLE 370 PDF about the indian constitution.
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
一比一原版(UM毕业证书)美国密歇根大学安娜堡分校毕业证如何办理
 
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
一比一原版(Cranfield毕业证书)克兰菲尔德大学毕业证如何办理
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理一比一原版悉尼大学毕业证如何办理
一比一原版悉尼大学毕业证如何办理
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
Police Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. SteeringPolice Misconduct Lawyers - Law Office of Jerry L. Steering
Police Misconduct Lawyers - Law Office of Jerry L. Steering
 

CyNation: 7 Things You Should Know about EU GDPR

  • 1. 7 things you should know about EU GDPR Shadi A. Razak 7th October 2016
  • 2. Introduction • Shadi A. Razak – Chief Technology Officer – Head of Compliance and Cyber Security Solutions – 15 international experience in: • Cyber security, • Information compliance • Business digitalisation – Private and public Sector – SMEs and International blue chip corporations
  • 3. Introduction We do that by providing innovative cyber security and information compliance solutions that encompass people, processes and technology, enabling organisations to become more resilient and effective against threats. We help organisations improve their compliance & security posture.
  • 4. Introduction Fraud Detection CyNation’s offers the most powerful yet easy to use analysis tools for detecting and preventing invisible internal fraud, external theft and poor procedural compliance. Ubiquitous Monitoring Combining an innovative object persistent database, advanced ubiquitous data collector with data analytics and high visualisation to proactively monitor multiple data types in one configurable system. Secure Communications CyNation’s Secure Communication Platform (SCP) protects confidential information flows between employees and external parties through a secure communications application that looks like email and is as easy to use as the popular instant messaging clients. Cyber Security Literacy Tailor-made workshops and training sessions for Boards, C-suite executives & management from cyber security awareness to cyber crisis incident response planning and simulation. GRC (Compliance Management) Combining human expertise with advanced data monitoring, data analytics & visualisation to proactively manage and comply with technical, operational, financial and legal standards and regulations. Comprehensive Threat Insight Combining advanced solutions of data analytics and visualisation to proactively manage and avert threats. Ongoing Risk Assessment Combining business risk assessments, advanced vulnerability assessments and penetration testing with data analytics to proactively assess and manage cyber risk.
  • 5. Agenda • The landscape • EU GDPR – Structure – Aim – Benefits – Consequences – Data Security • 7 things you should know • 7 Steps to be ready
  • 6. The landscape $ V.S Different legal system across the world Personal data is valuable Contrast between Europe & US legislation
  • 8. EU GDPR European Union General Data Protection Regulation General Provisions (Articles 1-4) Principles (Articles 5-11) Rights of Data Subjects: 5 Sections (Articles 12-23) Controller and Processors: 5 Section (Articles 24-43) Transfer of Personal Data (Articles 44-50) Independent Supervisory Authorities (Articles 51-59) Cooperation and Consistency (Articles 60-76) Remedies, Liabilities and Penalties (Articles 77-84) Processing Situation Provisions (Article 85-91) Delegation and Implementation Act (Article 92&93) Final Provisions (Articles 94-99) 1 2 3 4 5 6 7 8 9 10 11 The core of the regulation How supervisory authorities at the EU are going to enforce the regulation
  • 10. EU GDPR - Aim • One Regulation • Stronger enforcement body • Data Protection Impact Assessment (DPIA) • Include international suppliers in regulation scope • Diminish distinction between processor and controller
  • 11. EU GDPR - Benefits • For business: – One market : one law – One stop shop – Same rules for all companies – No general registration requirement
  • 12. EU GDPR - Benefits • For customers / citizens: – Better data security – Better control over your personal data: • Mandatory consent • Right to be forgotten • Right to object to profiling • Better subject access request (SAR) regime
  • 13. EU GDPR - Consequences • Fine of €10million or 2% of global turnover, whichever is greater: ꟷ 8: Child’s consent ꟷ 11: Processing not requiring identification ꟷ 25: Data protection by design and by default ꟷ 26 - 30: Processing ꟷ 31: Cooperation with the supervisory authority ꟷ 32: Data security ꟷ 33: Notification of breaches to supervisory authority ꟷ 34: Communication of breaches to data subjects ꟷ 35: Data protection impact assessment ꟷ 36: Prior consultation ꟷ 37 -39: DPOs ꟷ 41(4): Monitoring approved codes of conduct ꟷ 42: Certification ꟷ 43: Certification bodies
  • 14. EU GDPR - Consequences • Fine of €20million or 4% of global turnover, whichever is greater: – 5: Principles relating to the processing of personal data – 6: Lawfulness of processing – 7: Conditions for consent – 9: Processing special categories of personal data (i.e. sensitive personal data) – 12 - 22: Data subject rights – 44 - 49: Transfers to third countries – 58(1): Requirement to provide access to supervisory authority – 58(2): Orders/limitations on processing or the suspension of data flows
  • 15. EU GDPR - Consequences Audit failure Fines & criminal charges Financial loss Loss of data confidentiality, integrity and/or availability Violation of employee privacy Loss of customer Trust Loss of brand reputation Loss of market share Damaged reputation Legal exposure CEO CFO/COO CIO CHRO CMO Greater Reputation Risk
  • 16. EU GDPR – Data security • Chapter 4: – 4 Key articles: • Section 2: Security of personal data – Article 32: Security of Processing – Article 33: Notification of personal data breaches to the supervisory authority – Article 34: Communication of personal data breaches to the data subjects • Section 3: Data Protection Impact Assessment and Prior Consultation – Article 35: Data protection impact assessment
  • 17. EU GDPR – Data security Organisation must Organisation will • greatly reduce the likelihood of being fined • will not need to notify affected data subjects of the breach • Implement appropriate security measures to protect personal data • Have a clear data protection policy • Have named a data protection officer
  • 18. 7 Thing you should know EU GDPR is already a reality It is all about protecting the fundamental rights of natural person It applies to every organisation and every type of data Consent Rules Accountability and transparency are the organisation responsibility Data Protection Officer is needed Encryption is not the answer 1 2 3 4 5 6 7
  • 19. 7 steps to get ready 1 • Audit your data 2 • Identify who is responsible for this data 3 • Design and implement appropriate measure to protect this data 4 • Develop processes to deal with breaches/incidents 5 • Designate a Data protection Officer (DPO) and supporting team 6 • Understand who is data you are controlling and/or processing 7 • Develop culture of Privacy by design wide across the organisation
  • 20. 7 steps to get ready 1 • Audit your data 2 • Identify who is responsible for this data 3 • Design and implement appropriate measure to protect this data 4 • Develop processes to deal with breaches/incidents 5 • Designate a Data protection Officer (DPO) and supporting team 6 • Understand who is data you are controlling and/or processing 7 • Develop culture of Privacy by design wide across the organisation
  • 21. EU GDPR Readiness • Get your organisation EU GDPR Readiness report - December 2016 (contact@cynation.com)
  • 22. © Copyright CyNation Limited 2016. All rights reserved. Without the express prior written consent of the CyNation, the presentation and any information contained within it may not be (i) reproduced (in whole or in part), (ii) copied at any time, (iii)used for any purpose other than your evaluation of the company or (iv) provided to any other person, except your employees, and advisors with a need to know who are advised of the confidentiality of the information. The information contained in these materials is provided for informational purposes only, and is provided as is without warranty of any kind, express or implied. CyNation shall not be responsible for any damages arising out of the use of, or otherwise related to, these materials. Nothing contained in these materials is intended to, nor shall have the effect of, creating any warranties or representations from CyNation or its suppliers or licensors, or altering the terms and conditions of the applicable license agreement governing the use of CyNation solutions and services. Product release dates and / or capabilities referenced in these materials may change at any time at CyNation’s sole discretion based on market opportunities or other factors, and are not intended to be a commitment to future product or feature availability in any way. We would be delighted to talk to you: Shadi A. Razak shadi.razak@cynation.com T: +44(0)7768 686638