SlideShare ist ein Scribd-Unternehmen logo
1 von 4
Downloaden Sie, um offline zu lesen
What is GDPR?
General Data Protection Regulation (GDPR)1
is the new, overarching
regulation governing the security of personal data that applies to
all companies doing business in the European Union (EU). GDPR
grants EU citizens both the Right of Access2
to their personal data,
as well as the Right to be Forgotten3
.
With penalties of up to 4% of global revenues for any company
conducting business within the EU, the impact of GDPR will be
felt far beyond Europe. All companies doing business in the EU
will be impacted by GDPR. Financial institutions, already saddled
with burdensome regulation on personal data retention, will bear
the added burden of knowing what data must be destroyed. This
will include the requirement for an auditable record for every
spreadsheet, email, Word and PDF documents containing personal
data on EU citizens. Within those files, each piece of data will need
to be tagged for mandatory retention or disposal.
The process for tagging will need to be designed to continually
resolve conflicts between GDPR and other regulations. Further,
these processes will need to capture each iteration of documents
drafted across all parts of each data collection process. The number
of draft documents are generally multiples of the final ones used
for compliance with Anti-Money Laundering (AML), Know-Your-
Customer (KYC), Base Erosion and Profit Shifting (BEPS) and other
financial regulations. In our estimation, the complexity of these
REGULATORY PERSPECTIVES
January 10th
, 2017
Volume - 1
Series - 2
By Jeb Beckwith – Managing Director, GreenPoint Financial
and Sanjay Sharma, Ph.D. – Chairman, GreenPoint Financial
GreenPoint>
Financial
sanjay@greenpoint.financial
jeb@greenpoint.financial
www.greenpoint.financial
DATA COMPLIANCE PENALTIES COULD COST YOU 4% OF GLOBAL REVENUES!
Fasten Your Belts for GDPR
2
already burdensome tasks will more than
double under GDPR.
Why Non-European Companies Should Care
GDPR imposes rules and restrictions on the
personal data of all EU citizens regardless of
where that data resides, how it is used, or
how it was originated. The penalty for non-
compliance also applies to companies that
have only a small part of their business but
fines are assessed on global revenues and
can be substantial (upto 4%). Examples
of companies which could fall under the
GDPR purview include a U.S. broker-dealer
distributing bonds through a European
platform, a Japanese bank issuing retail
notes to European investors, a Canadian
wealth management platform servicing
European clients, or a U.S. private equity firm
with EU citizens as investors. Even banks
without a European presence but servicing
the correspondent banking needs of their
European clients could be ensnared in the
GDPR regulation.
The Need for Centralized Control
For most financial institutions, centralization of
GDPR compliance should be mandatory. The
regulation itself requires the appointment for
a centralized Data Protection Officer (DPO)
if a company is a:
1)	Public authority, or an
2)	Organization that engages in large scale
systematic monitoring, or an
3)	Organization that engages in large scale
processing of sensitive personal data.4
AML/KYC regulation in most jurisdictions
currently requires financial institutions to
engage in “systemic monitoring” of personal
data, thus causing most financial institutions
to be classified under category 2 above. Even
if that were that not the case, the penalties
potentially imposed on the global enterprise
for the regional non-compliance of a single
business dictate that centralized data
management and reporting is necessary.
Penalties for Non-Compliance
Thankfully, first infractions will generally
receive only a written warning, particularly
for unintentional offenses. Repeated non-
compliance will be subject to harsher
penalties. The guidelines prescribed for
assessment of fines fall into two categories:
1)	Less Severe Infractions: Up to the
greater of €10MM or 2% of gross
revenues for:
a.	 Violations of the generic Data
Controller obligations5
b.	Violations of the generic Certification
Body obligations6
c.	 Violations of the generic Monitoring
Body obligations7
.
2)	More Severe Infractions: Up to the
greater of €20MM or 4% of gross
revenues for:
a.	 Violations of basic principles, in
particular, those relating to Consent
(see below)8
b.	Violations of Data Subject’s rights of
access and to be forgotten9
c.	 Transfer of personal data to a recipient
in a foreign country or an international
organization10
d.	Valuations of any Member State law11
e.	 Non-compliance with an order from a
Supervisory Authority12
.
Other Key Facts
‱	 Effective Date: May 25th
, 2018
‱	 Regulation vs. Directive: Under EU law,
directives must be implemented regionally
by the local jurisdictions within the EU.
Regulations, on the other hand, carry
the weight of law at the outset. On May
25th
, the GDPR regulation will replace the
prior directive. There will be no additional
implementation required.
‱	 Definition of Personal Data: Any
information related to a natural person
defined as a “Data Subject”. This broad
definition is not limited to name, address
and phone number, but also includes email
addresses, account numbers, photos, posts
on social networking sites, medical records,
and computer IP addresses. Information
could be collected proactively, as with utility
bills for KYC due diligence, or incidentally,
as in an employee viewing the Facebook
post of an EU citizen.
3
‱	 Data Breach Reporting: Actual or
potential data breaches must be reported
within 72 hours, not only to the authorities,
but also to the affected parties. Such
breaches must include a description of the
information at risk, which implies that the
institution must have auditable records of
all information they have on file.
‱	 Authority for Data Processing:
Companies may only lawfully process
personal data if one of the following
conditions exists:
1)	Consent has been obtained from the
Data Subject (see consent definition
below)
2)	Data Subject is party to or has requested
a contract which requires processing
3)	Data Controller has a legal obligation to
process data
4)	“Vital interests” of the Data subject
or another natural person must be
protected
5)	Data Controller must perform a task in
the public interest or in the exercise of an
official authority
6)	“Processing is necessary for the purposes
of the legitimate interests pursued by
the controller or by a third party, except
where such interests are overridden
by the interests or fundamental rights
and freedoms of the data subject which
require protection of personal data,
specifically where the data subject is a
child”13
.
‱	 Consent: GDPR defines two types of
permissible consent.
1)	Explicit Opt-In Consent: Using clear
and plain language, separate and apart
from any other executed agreements, the
Data Subject must give explicit consent
for sensitive data to be processed by
a company. A failure for such explicit
consent defaults to an automatic “opt-
out” of such consent.
2)	Unambiguous Consent: Unambiguous
consent can be used for non-
sensitive data, be must still be granted
through a clear and transparent form
understandable to a layperson
‱	 Pseudonymisation: GDPR defines
pseudonymisation as the process of
transforming personal data into non-
attributable, portfolio data through the
use of encryption or by other means.
Although GDPR encourages the use
of pseudonymisation, this does NOT
mitigate the need to track personal data
transformed in this way. Not only does
pseudonymisated data remain subject to
GDPR requirements, but encryption keys
must be separately stored and tracked
from the transformed portfolio data with
the original data reconstructable. Specific
personal data must be destroyable upon
request from the Data Subject.
Actions to Take Today
The field of End-User-Computing (EUC)
can provide most companies with clear,
transparent, and auditable views of their client
data across multiple sources (XL, Word, email,
databases, etc.) in a centralized format without
interfering with the daily business of other
activity. The process of implementing robust
EUC procedures can be straightforward or
complex, depending upon the organization
and business structure, but in any event,
it will be a necessary requirement for any
financial institution operating in the E.U. or
interacting with E.U. entities. By far, the most
challenging obstacle for most companies is
to define ownership and accountability for
GDPR compliance. We provide the following
guidelines that should be implemented across
business lines and support functions.
‱	 Senior Management:
1)	Appoint a Chief Data Protection
Officer (CDPO). This may be a new
position or additional duties for an
existing employee. In either case, GDPR
accountability should be assigned to a
single management professional or a
functional group. The CDPO function
should be tasked with developing and
implementing firm-wide technology,
policies, and procedures which
demonstrate GDPR compliance at a
robust and granular level.
2)	Educate senior staff and business heads
of the financial consequences for non-
compliance to ensure robust cooperation
with the CDPO.
4
1.	 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April, 2016 found here http://
ec.europa.eu/justice/data-protection/reform/files/regulation_oj_en.pdf
2.	 Ibid, Article 15
3.	 Ibid, Article 17
4.	 Ibid, Article 37
5.	 Ibid, Articles 8, 11, 25-39, 42-43
6.	 Ibid, Articles 42-43
7.	 Ibid, Article 41(4)
8.	 Ibid, Articles 5-7, 9
9.	 Ibid, Article 12-22
10.	 Ibid, Article 44-49
11.	 Ibid, Chapter IX
12.	 Ibid, Article 58 (1)
13.	 Ibid
3)	Task the audit function with creating
clear criteria for validation of policies and
procedures developed by the CDPO.
‱	 CDPO:
1)	Inform the education process sponsored
by senior management for the entire
organization.
2)	Deploy comprehensive and robust EUC
software across the organization. GDPR
requires centralized reporting which is
only practical by using sophisticated EUC
tools. This will also alleviate the need
for regular intrusive interactions with
business lines.
3)	Establish policies and procedures for
GDPR compliance which consider existing
regulation and clearly articulate how
potential conflicts should be handled.
4)	Vet policies/procedures with experienced
advisors and/or authorities and adjust
based in recommendations prior to
implementation.
5)	Monitor and report variances and
exceptions regularly and report to
management on a quarterly basis at a
minimum.
‱	 Audit:
1)	Create clear criteria for compliance with
policies and procedures created by the
CDPO
2)	Conduct audits at least annually and
consistent with other activities that are
classified to entail high operational
risks.

Weitere Àhnliche Inhalte

Was ist angesagt?

GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.Steven Salter
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?David Erdos
 
The GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyThe GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyLilian Edwards
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDavid Erdos
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guideAngad Dayal
 
Brexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK PerspectiveBrexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK PerspectiveTrustArc
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT worksMorris Dorfer
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookPlr-Printables
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanEquiGov Institute
 
TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...
TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...
TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...TrustArc
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization Vishnuvarthanan Moorthy
 
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...MediaPost
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non expertsClaudio Bolla, CISM
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.Matthias Dobbelaere-Welvaert
 

Was ist angesagt? (19)

GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
The GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyThe GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacy
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
 
GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
 
Brexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK PerspectiveBrexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK Perspective
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e bookGDPR, what you need to know and how to prepare for it e book
GDPR, what you need to know and how to prepare for it e book
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
DPA and GDPR
DPA and GDPRDPA and GDPR
DPA and GDPR
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...
TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...
TrustArc Webinar: How to Prepare Your Business for Privacy Changes in the Mid...
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization
 
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
Data Protection Reform: What Businesses Need to know About GDPR and its Impac...
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
 

Ähnlich wie Fasten Your Belts for #GDPR

The Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsThe Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsHubilo
 
All you need to know about GDPR
All you need to know about GDPRAll you need to know about GDPR
All you need to know about GDPRHubilo
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaperJim Wilson
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
GDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmGDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmChris White
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan Ulf Mattsson
 
GDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the BankGDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the Bank"John "Jeb"" Beckwith
 
Aon GDPR white paper
Aon GDPR white paperAon GDPR white paper
Aon GDPR white paperGraeme Cross
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisAngad Dayal
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUESSylvain Martinez
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulationFahad Ameen
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
Are You Prepared for the GDPR?
Are You Prepared for the GDPR?Are You Prepared for the GDPR?
Are You Prepared for the GDPR?PrivacyPolicies.com
 
GDPR
GDPRGDPR
GDPRGopi PD
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-OverviewErica Walker
 
Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)Kwanko
 

Ähnlich wie Fasten Your Belts for #GDPR (20)

The Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event ProfessionalsThe Definitive GDPR Guide for Event Professionals
The Definitive GDPR Guide for Event Professionals
 
All you need to know about GDPR
All you need to know about GDPRAll you need to know about GDPR
All you need to know about GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
GDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, EcosystmGDPR & You, Claus Mortensen, Ecosystm
GDPR & You, Claus Mortensen, Ecosystm
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the BankGDPR Solutions That Won't Break the Bank
GDPR Solutions That Won't Break the Bank
 
Aon GDPR white paper
Aon GDPR white paperAon GDPR white paper
Aon GDPR white paper
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with Varonis
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulation
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Are You Prepared for the GDPR?
Are You Prepared for the GDPR?Are You Prepared for the GDPR?
Are You Prepared for the GDPR?
 
GDPR
GDPRGDPR
GDPR
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)
 

Mehr von "John "Jeb"" Beckwith

Regulatory Trading Desk (RTD) optimization
Regulatory Trading Desk (RTD) optimizationRegulatory Trading Desk (RTD) optimization
Regulatory Trading Desk (RTD) optimization"John "Jeb"" Beckwith
 
Managing Non-Modellable Risk Factors
Managing Non-Modellable Risk FactorsManaging Non-Modellable Risk Factors
Managing Non-Modellable Risk Factors"John "Jeb"" Beckwith
 
Basel III - New Timeline, Same Issues
Basel III - New Timeline, Same IssuesBasel III - New Timeline, Same Issues
Basel III - New Timeline, Same Issues"John "Jeb"" Beckwith
 
GreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SA
GreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SAGreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SA
GreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SA"John "Jeb"" Beckwith
 
GreenPoint Financial Perspectives - Summer 2017
GreenPoint Financial Perspectives - Summer 2017GreenPoint Financial Perspectives - Summer 2017
GreenPoint Financial Perspectives - Summer 2017"John "Jeb"" Beckwith
 

Mehr von "John "Jeb"" Beckwith (6)

Regulatory Trading Desk (RTD) optimization
Regulatory Trading Desk (RTD) optimizationRegulatory Trading Desk (RTD) optimization
Regulatory Trading Desk (RTD) optimization
 
Managing Non-Modellable Risk Factors
Managing Non-Modellable Risk FactorsManaging Non-Modellable Risk Factors
Managing Non-Modellable Risk Factors
 
Fasten Your Belts for GDPR
Fasten Your Belts for GDPRFasten Your Belts for GDPR
Fasten Your Belts for GDPR
 
Basel III - New Timeline, Same Issues
Basel III - New Timeline, Same IssuesBasel III - New Timeline, Same Issues
Basel III - New Timeline, Same Issues
 
GreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SA
GreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SAGreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SA
GreenPoint Regulatory Perspectives - A Simplified Alternative to BCBS SA
 
GreenPoint Financial Perspectives - Summer 2017
GreenPoint Financial Perspectives - Summer 2017GreenPoint Financial Perspectives - Summer 2017
GreenPoint Financial Perspectives - Summer 2017
 

KĂŒrzlich hochgeladen

Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaShree Krishna Exports
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insightsseri bangash
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdftbatkhuu1
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 DelhiCall Girls in Delhi
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyEthan lee
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetDenis Gagné
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 

KĂŒrzlich hochgeladen (20)

Best Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in IndiaBest Basmati Rice Manufacturers in India
Best Basmati Rice Manufacturers in India
 
Understanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key InsightsUnderstanding the Pakistan Budgeting Process: Basics and Key Insights
Understanding the Pakistan Budgeting Process: Basics and Key Insights
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
VVVIP Call Girls In Greater Kailash âžĄïž Delhi âžĄïž 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash âžĄïž Delhi âžĄïž 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash âžĄïž Delhi âžĄïž 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash âžĄïž Delhi âžĄïž 9999965857 🚀 No Advance 24HRS...
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Event mailer assignment progress report .pdf
Event mailer assignment progress report .pdfEvent mailer assignment progress report .pdf
Event mailer assignment progress report .pdf
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
9599632723 Top Call Girls in Delhi at your Door Step Available 24x7 Delhi
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow â‚č,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow â‚č,9517Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow â‚č,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow â‚č,9517
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature SetCreating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
Creating Low-Code Loan Applications using the Trisotech Mortgage Feature Set
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 

Fasten Your Belts for #GDPR

  • 1. What is GDPR? General Data Protection Regulation (GDPR)1 is the new, overarching regulation governing the security of personal data that applies to all companies doing business in the European Union (EU). GDPR grants EU citizens both the Right of Access2 to their personal data, as well as the Right to be Forgotten3 . With penalties of up to 4% of global revenues for any company conducting business within the EU, the impact of GDPR will be felt far beyond Europe. All companies doing business in the EU will be impacted by GDPR. Financial institutions, already saddled with burdensome regulation on personal data retention, will bear the added burden of knowing what data must be destroyed. This will include the requirement for an auditable record for every spreadsheet, email, Word and PDF documents containing personal data on EU citizens. Within those files, each piece of data will need to be tagged for mandatory retention or disposal. The process for tagging will need to be designed to continually resolve conflicts between GDPR and other regulations. Further, these processes will need to capture each iteration of documents drafted across all parts of each data collection process. The number of draft documents are generally multiples of the final ones used for compliance with Anti-Money Laundering (AML), Know-Your- Customer (KYC), Base Erosion and Profit Shifting (BEPS) and other financial regulations. In our estimation, the complexity of these REGULATORY PERSPECTIVES January 10th , 2017 Volume - 1 Series - 2 By Jeb Beckwith – Managing Director, GreenPoint Financial and Sanjay Sharma, Ph.D. – Chairman, GreenPoint Financial GreenPoint> Financial sanjay@greenpoint.financial jeb@greenpoint.financial www.greenpoint.financial DATA COMPLIANCE PENALTIES COULD COST YOU 4% OF GLOBAL REVENUES! Fasten Your Belts for GDPR
  • 2. 2 already burdensome tasks will more than double under GDPR. Why Non-European Companies Should Care GDPR imposes rules and restrictions on the personal data of all EU citizens regardless of where that data resides, how it is used, or how it was originated. The penalty for non- compliance also applies to companies that have only a small part of their business but fines are assessed on global revenues and can be substantial (upto 4%). Examples of companies which could fall under the GDPR purview include a U.S. broker-dealer distributing bonds through a European platform, a Japanese bank issuing retail notes to European investors, a Canadian wealth management platform servicing European clients, or a U.S. private equity firm with EU citizens as investors. Even banks without a European presence but servicing the correspondent banking needs of their European clients could be ensnared in the GDPR regulation. The Need for Centralized Control For most financial institutions, centralization of GDPR compliance should be mandatory. The regulation itself requires the appointment for a centralized Data Protection Officer (DPO) if a company is a: 1) Public authority, or an 2) Organization that engages in large scale systematic monitoring, or an 3) Organization that engages in large scale processing of sensitive personal data.4 AML/KYC regulation in most jurisdictions currently requires financial institutions to engage in “systemic monitoring” of personal data, thus causing most financial institutions to be classified under category 2 above. Even if that were that not the case, the penalties potentially imposed on the global enterprise for the regional non-compliance of a single business dictate that centralized data management and reporting is necessary. Penalties for Non-Compliance Thankfully, first infractions will generally receive only a written warning, particularly for unintentional offenses. Repeated non- compliance will be subject to harsher penalties. The guidelines prescribed for assessment of fines fall into two categories: 1) Less Severe Infractions: Up to the greater of €10MM or 2% of gross revenues for: a. Violations of the generic Data Controller obligations5 b. Violations of the generic Certification Body obligations6 c. Violations of the generic Monitoring Body obligations7 . 2) More Severe Infractions: Up to the greater of €20MM or 4% of gross revenues for: a. Violations of basic principles, in particular, those relating to Consent (see below)8 b. Violations of Data Subject’s rights of access and to be forgotten9 c. Transfer of personal data to a recipient in a foreign country or an international organization10 d. Valuations of any Member State law11 e. Non-compliance with an order from a Supervisory Authority12 . Other Key Facts ‱ Effective Date: May 25th , 2018 ‱ Regulation vs. Directive: Under EU law, directives must be implemented regionally by the local jurisdictions within the EU. Regulations, on the other hand, carry the weight of law at the outset. On May 25th , the GDPR regulation will replace the prior directive. There will be no additional implementation required. ‱ Definition of Personal Data: Any information related to a natural person defined as a “Data Subject”. This broad definition is not limited to name, address and phone number, but also includes email addresses, account numbers, photos, posts on social networking sites, medical records, and computer IP addresses. Information could be collected proactively, as with utility bills for KYC due diligence, or incidentally, as in an employee viewing the Facebook post of an EU citizen.
  • 3. 3 ‱ Data Breach Reporting: Actual or potential data breaches must be reported within 72 hours, not only to the authorities, but also to the affected parties. Such breaches must include a description of the information at risk, which implies that the institution must have auditable records of all information they have on file. ‱ Authority for Data Processing: Companies may only lawfully process personal data if one of the following conditions exists: 1) Consent has been obtained from the Data Subject (see consent definition below) 2) Data Subject is party to or has requested a contract which requires processing 3) Data Controller has a legal obligation to process data 4) “Vital interests” of the Data subject or another natural person must be protected 5) Data Controller must perform a task in the public interest or in the exercise of an official authority 6) “Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, specifically where the data subject is a child”13 . ‱ Consent: GDPR defines two types of permissible consent. 1) Explicit Opt-In Consent: Using clear and plain language, separate and apart from any other executed agreements, the Data Subject must give explicit consent for sensitive data to be processed by a company. A failure for such explicit consent defaults to an automatic “opt- out” of such consent. 2) Unambiguous Consent: Unambiguous consent can be used for non- sensitive data, be must still be granted through a clear and transparent form understandable to a layperson ‱ Pseudonymisation: GDPR defines pseudonymisation as the process of transforming personal data into non- attributable, portfolio data through the use of encryption or by other means. Although GDPR encourages the use of pseudonymisation, this does NOT mitigate the need to track personal data transformed in this way. Not only does pseudonymisated data remain subject to GDPR requirements, but encryption keys must be separately stored and tracked from the transformed portfolio data with the original data reconstructable. Specific personal data must be destroyable upon request from the Data Subject. Actions to Take Today The field of End-User-Computing (EUC) can provide most companies with clear, transparent, and auditable views of their client data across multiple sources (XL, Word, email, databases, etc.) in a centralized format without interfering with the daily business of other activity. The process of implementing robust EUC procedures can be straightforward or complex, depending upon the organization and business structure, but in any event, it will be a necessary requirement for any financial institution operating in the E.U. or interacting with E.U. entities. By far, the most challenging obstacle for most companies is to define ownership and accountability for GDPR compliance. We provide the following guidelines that should be implemented across business lines and support functions. ‱ Senior Management: 1) Appoint a Chief Data Protection Officer (CDPO). This may be a new position or additional duties for an existing employee. In either case, GDPR accountability should be assigned to a single management professional or a functional group. The CDPO function should be tasked with developing and implementing firm-wide technology, policies, and procedures which demonstrate GDPR compliance at a robust and granular level. 2) Educate senior staff and business heads of the financial consequences for non- compliance to ensure robust cooperation with the CDPO.
  • 4. 4 1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April, 2016 found here http:// ec.europa.eu/justice/data-protection/reform/files/regulation_oj_en.pdf 2. Ibid, Article 15 3. Ibid, Article 17 4. Ibid, Article 37 5. Ibid, Articles 8, 11, 25-39, 42-43 6. Ibid, Articles 42-43 7. Ibid, Article 41(4) 8. Ibid, Articles 5-7, 9 9. Ibid, Article 12-22 10. Ibid, Article 44-49 11. Ibid, Chapter IX 12. Ibid, Article 58 (1) 13. Ibid 3) Task the audit function with creating clear criteria for validation of policies and procedures developed by the CDPO. ‱ CDPO: 1) Inform the education process sponsored by senior management for the entire organization. 2) Deploy comprehensive and robust EUC software across the organization. GDPR requires centralized reporting which is only practical by using sophisticated EUC tools. This will also alleviate the need for regular intrusive interactions with business lines. 3) Establish policies and procedures for GDPR compliance which consider existing regulation and clearly articulate how potential conflicts should be handled. 4) Vet policies/procedures with experienced advisors and/or authorities and adjust based in recommendations prior to implementation. 5) Monitor and report variances and exceptions regularly and report to management on a quarterly basis at a minimum. ‱ Audit: 1) Create clear criteria for compliance with policies and procedures created by the CDPO 2) Conduct audits at least annually and consistent with other activities that are classified to entail high operational risks.