SlideShare ist ein Scribd-Unternehmen logo
1 von 52
• Overview Of Privacy & Data Protection (P&DP)
• Current Status on P&DP
• New and updated Privacy Legislations
• Commonalities between legislations
• What is the impact?
• Global P&DP trends
• Q & A
Agenda
Introduction
Before we start…
Check the past webinars on the PECB website at
• https://pecb.com/past-webinars
Find all sessions with Q&A + collaterals (decks, recording) at:
http://ffwd2.me/PECB_ISO27001_webinars (short cut to LinkedIN page)
Previous sessions
After the session, you can find the presentation and recording at
• https://pecb.com/past-webinars
Reference information + Q&A of this session:
https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-2021-compliance-
new-peter-geelen-/
This session collaterals
Overview Of Privacy & Data Protection
(P&DP)
What's in a word…
Data Privacy Definition
Information privacy is the relationship between the collection and dissemination of
data, technology, the public expectation of privacy, and the legal and political
issues surrounding them.*
*https://en.wikipedia.org/wiki/Information_privacy
Data Protection
GDPR Art. 1.1:
"protection of natural persons with regard to the
processing of personal data and rules relating to the
free movement of personal data"
*https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32016R0679
GDPR and privacy
GDPR itself does not mention privacy…
except a footnote on Directive 2002/58/EC, the eCommunications
directive
In GDPR, it's about data protection, which means protecting your
data.
Privacy = "The right to be left alone"
Some Stats – UN Conference on Trade & Development
Privacy, data protection vs. cybersecurity
There is
No Privacy and data protection
Without
Cybersecurity
But you can have cybersecurity without the need of privacy or
data protection.
Privacy & Data Protection vs Enterprise security
In many cases
• Privacy & data protection is targeted to people, persons and
their data
• Privacy & data protection is (mostly) not about company or
enterprise data (finance, operations, products, services…)
BUT
Data breaches of company data do have the same impact (so
treat and protect them equally)
Current Status on P&DP
The battle for your personal data
and privacy
North America - Canada
PIPEDA - Personal Information Protection and Electronic Documents Act
• Federal Legislation managed by the Office of the Privacy Commissioner of Canada
• An individual’s consent must be obtained for the collection, use or disclosure of their personal
information; individuals have the right to access their personal information and to challenge
any inaccuracies in it.
• Personal information can inly be used for the purposes for which it was collected otherwise
consent must be obtained again.
• Personal information must be appropriately protected.
• Applies to private sector organizations in Canada.
• Is supplemented by privacy laws at the Provincial level in Canada (e.g., laws in Ontario versus
Quebec, etc.).
• Data that crosses borders, whether within Canada or internationally, is a concern.
• Fines: up to $100,000 CAD
North America - Canada
Other laws:
• CASL – Canada Anti Spam Legislation
• Federal law
• Requires individual’s expressed or implied consent, depending
upon the situation
• Requires unsubscribe mechanism
• Up to $1 million CAD fine per violation and up to $10 million CAD
fine for corporations
Each Province/Territory in Canada, has its own privacy and health data
protection laws but each aligns with PIPEDA and then augments
PIPEDA with regional guidance.
North America - Canada
Multiple laws and legislations across Canada at the Provincial
level.
North America - Canada
Advice:
• Become familiar with both the Federal and Provincial
laws and legislations before you assume that you are
managing personal data correctly
Important: better apply this to any privacy & data
protection implementation, not only to USA/CA region.
North America - USA
E-Sign – Electronic Signatures in Global and National
Commerce Act
• Describes and validates electronic forms of data including e-
signatures
HIPAA – Health Insurance Portability and Accountability Act of
1996
• Protects privacy of personal health information
• Carries penalties of from $100 USD to $50,000 USD per record
violation
North America - USA
California Consumer Privacy Act
• Applies to any organization that does business in California and which has
gross revenues in excess of $25 million USD or that has 50,000 or more
personal records or that earns ½+ of its revenue from selling personal
information
• Penalties of from $2,500 to $7,500 USD per violation
NY Shield Act
• If you hold any personal or private data of any New York resident, this applies
to you
• Penalties of $5,000 USD or $20 USD per violation up to $250,000 USD
Maximum
Central and South America
Mexico - Federal Law on Personal Data Held by Private Parties (FLPPDPP)
• Applies to private sector
• Oddly, no need to inform any government body should a breach occur
Chile- Law No. 19.628 on the Protection of Private Life 1999
• Under development but will align with international privacy laws and standards
Brazil – Law No. 13.709 – General Personal Data Protection Law
• Into effect in September 2020 but will be enforced beginning August 2021
• Similar to GDPR with DPO’s required, data breach and transfer requirements, and privacy
impact assessments
• Established history of enforcement WRT privacy
Other Countries in Central and South America have currently implemented, draft or in progress
privacy laws with only a few countries/locations in Central & South America and the Caribbean with
no privacy laws (oddly, Puerto Rico has none).
Europe
Type of law (Source: EC)
• Regulation
• Regulations are legal acts that apply automatically and uniformly to all EU
countries as soon as they enter into force,
• without needing to be transposed into national law.
• They are binding in their entirety on all EU countries.
• Directive
• Directives require EU countries to achieve a certain result, but leave them
free to choose how to do so. EU countries must adopt measures to
incorporate them into national law (transpose) in order to achieve the
objectives set by the directive.
Europe
GDPR
• Data protection (not privacy)
• Regulation
• Tuned with national legislation
Europe
Other legislation that impact privacy & data protection
• eCommunications & eCommerce
• ePrivacy directive (in review/update)
But also
• NIS (cybersecurity for public & critical infrastructure)
• NIS v2 coming up
• CyberAct
New and updated Privacy Legislations
Keep an eye on…
North America - Canada
CCPA – Consumer Privacy Protection Act
• Enhancement to PIPEDA
• Privacy and Data Protection Tribunal is established.
• Same acronym as the California Consumer Protection Act (also, CCPA) but
aims to be even stronger.
• Organizations must maintain a privacy management program; meaningful
consent must be obtained; deidentified data is covered; right to erasure;
enhanced enforcement.
• Private lawsuits for violations are permitted.
• Third-party service providers are in scope.
• Penalties for non-compliance: up to 3% of global revenue or $10 million CAD
OR up to 5% of global revenue or $25 million CAD for serious breaches.
Europe
GDPR Processing principles
• eCommunications & eCommerce
• High impact on direct marketing
• ePrivacy directive (in review/update)
• Aligned with GDPR
• High impact on direct marketing
• NIS (cybersecurity for public & critical infrastructure)
• NIS v2 coming up
• CyberAct (Cyber certification, PPT, …)
Commonalities between legislations
Comparing and understanding the context of
the legislations
Some Common Features
• Privacy officer : Like the GDPR requirement, many privacy laws across the world are
looking to have a personal appointed in your organization who is accountable for
privacy.
• Penalties : As we have seen with GDPR and with HIPAA in the USA, financial
penalties for violations of privacy legislation or even for improper breach handling can
be costly both in terms of monetary cost as well as reputational impact.
• Privacy Program : Privacy legislations are increasingly looking for organizations to
have a privacy program in place (e.g., privacy policy(ies), breach management plan,
privacy awareness training for staff, etc.).
• Breach Management and Notification : It is critical to have a documented data
breach management plan that also includes a breach notification process.
• Consent : Consent for the collection of personal data that includes a precise
description of the planned use for the data is critical.
• Note that many privacy or data protection laws include the publishing of data breaches
or infractions of the privacy legislation. (“Name and Shame”)
North America - Canada
CCPA – Consumer Privacy Protection Act
• Enhancement to PIPEDA
• Privacy and Data Protection Tribunal is established.
• Same acronym as the California Consumer Protection Act (also, CCPA) but
aims to be even stronger.
• Organizations must maintain a privacy management program; meaningful
consent must be obtained; deidentified data is covered; right to erasure;
enhanced enforcement.
• Private lawsuits for violations are permitted.
• Third-party service providers are in scope.
• Penalties for non-compliance: up to 3% of global revenue or $10 million CAD
OR up to 5% of global revenue or $25 million CAD for serious breaches.
Europe
GDPR Processing principles
• Principles (Art. 5) (lawful, fairly, transparent, …)
• Lawfulness of processing Art. 6
consent,
Contract,
legal oblication,
vital interest,
public interest,
legitimate interest
Europe
GDPR Subject Rights
• Conditions for consent (incl. minors/children)
• Special categories of data
• Rights
Right of access
Right to rectification
Right to be forgotten
Right to restrict processing
Right to notification
Right to data portability
Right to object
Europe
GDPR Obligations - Data controllers & data processors
• Data protection by default
• Data protection by design
• Joint controllers
• Record of processing (processing register)
• Data breach management (incl. notifications)
• Security of processing
• DPIA
Europe
GDPR Obligations - Data controllers & data processors
• DPO (data protection officer)
Designation (public authoriticy, large scale, sensitive data)
Position (independent, advisory, …)
Tasks
Inform & advice
Monitor compliance
Cooperate with DPA
SoD: NOT responsible/accountable for DC/DP tasks
Europe
GDPR Fines
• Purpose: in each individual case , to be
effective,
proportionate and
dissuasive
• Depending the nature, gravity and duration of the infringement
infringement
2% or €10M
4% or €20M
What is the impact?
Europe
Data protection authorities in action… a trend.
There are various sites that follow up on the GDPR fines
For example:
• https://www.enforcementtracker.com/
• https://www.coreview.com/blog/alpin-gdpr-fines-list/
• https://www.privacyaffairs.com/gdpr-fines/
• …
In general
• Powerful subject
• Data controllers balancing between
• Subject rights
• Government
• Commercial interest
• Cross border impact of legislation
GDPR is not only for EU companies or EU citizens
P&DP new trends
Privacy & Data protection is HOT
• Driver: Cybercrime/breach impact grows
• Commercial impact vs subjects
• Existing Social media platforms have difficulties to find the
new way of working aligned with regulations
• New platforms don't get it always right
• Take back privacy
Very low level of protection of internet data
Free flow of data, now issue…
Privacy & Data protection is HOT
• Cookies management
• Dark patterns ("Accept All", before you find the "configure button")
• Cookie psychology
• Direct marketing
Data brokers position
Collection of data vs obligations of transparency
Public data vs purpose definitions
• Cross border, international impact
Data brokers out of reach
Privacy & Data protection is HOT
And also…
• IoT Security impact on P&DP
• Camera's
• Cars
• Toys
• …
References
Interesting information sources
Reference material
Collateral references and additional info posted on
• https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-
2021-compliance-new-peter-geelen-/
ISO/IEC 27701
Training Courses
• ISO/IEC 27701 Foundation
2 Day Course
• ISO/IEC 27701 Lead Implementer
5Days Course
Exam and certification fees are included in the training price.
https://pecb.com/en/education-and-certification-for-individuals/iso-
27701
www.pecb.com/events
Appendix
Ramping up…
Relevant PECB Training courses
Relevant Training
PIMS
• PECB ISO 27701 Foundation
• PECB ISO 27701 LI
• PECB ISO 27701 LA
Information Security
• PECB ISO 27001 LI
• PECB ISO 27001 LA
• PECB ISO 27002 LM
Relevant Training
Data protection
• PECB Certified Data protection Officer (GDPR)
Privacy
• PECB ISO29100 LI
Other Relevant Training
Incident Management
• PECB ISO 27035 LI
Risk Management
• PECB ISO 27005 LI
Check the PECB agenda, select the ISO/IEC 27701 Lead
Implementer
https://pecb.com/en/partnerEvent/event_schedule_list
Training Events
For full detailed information about an event click on the ‘View’ button on the right hand
side under ‘View full details’.
Note: Before applying for any training courses listed below, please make sure you are
registered to PECB
Training Agenda
THANK YOU
?
info@cyberminute.com CyberMinute
asenglish@hotmail.com BOT Security Solutions

Weitere ähnliche Inhalte

Was ist angesagt?

The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
SaimaRafiq
 

Was ist angesagt? (20)

Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in India
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
ISO 27001
ISO 27001ISO 27001
ISO 27001
 
Information Technology Policy for Corporates - Need of the Hour
Information Technology Policy for Corporates - Need of the Hour Information Technology Policy for Corporates - Need of the Hour
Information Technology Policy for Corporates - Need of the Hour
 
Data protection
Data protectionData protection
Data protection
 
General Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) ComplianceGeneral Data Protection Regulation (GDPR) Compliance
General Data Protection Regulation (GDPR) Compliance
 
Data protection
Data protectionData protection
Data protection
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
GDPR
GDPRGDPR
GDPR
 
Data Protection Presentation
Data Protection PresentationData Protection Presentation
Data Protection Presentation
 
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
ISO/IEC 27701, GDPR, and ePrivacy: How Do They Map?
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection Bill
 
Any Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO StandardsAny Standard is Better Than None: GDPR and the ISO Standards
Any Standard is Better Than None: GDPR and the ISO Standards
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
Basic introduction to iso27001
Basic introduction to iso27001Basic introduction to iso27001
Basic introduction to iso27001
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
IT Security management and risk assessment
IT Security management and risk assessmentIT Security management and risk assessment
IT Security management and risk assessment
 

Ähnlich wie Data Privacy Trends in 2021: Compliance with New Regulations

The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
Rachel Aldighieri
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
Rachel Aldighieri
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
Rachel Aldighieri
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Constantine Karbaliotis
 

Ähnlich wie Data Privacy Trends in 2021: Compliance with New Regulations (20)

Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analytics
 
Cloud primer
Cloud primerCloud primer
Cloud primer
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to know
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 
Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)
 

Mehr von PECB

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
PECB
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
PECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
PECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
PECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
PECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
PECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
PECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
PECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
PECB
 

Mehr von PECB (20)

Beyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global ImpactBeyond the EU: DORA and NIS 2 Directive's Global Impact
Beyond the EU: DORA and NIS 2 Directive's Global Impact
 
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 

Kürzlich hochgeladen

Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
ZurliaSoop
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
heathfieldcps1
 

Kürzlich hochgeladen (20)

Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
Jual Obat Aborsi Hongkong ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan...
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
 
How to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptxHow to setup Pycharm environment for Odoo 17.pptx
How to setup Pycharm environment for Odoo 17.pptx
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
 
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
On National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan FellowsOn National Teacher Day, meet the 2024-25 Kenan Fellows
On National Teacher Day, meet the 2024-25 Kenan Fellows
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
 
How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and Modifications
 

Data Privacy Trends in 2021: Compliance with New Regulations

  • 1.
  • 2. • Overview Of Privacy & Data Protection (P&DP) • Current Status on P&DP • New and updated Privacy Legislations • Commonalities between legislations • What is the impact? • Global P&DP trends • Q & A Agenda
  • 5. Check the past webinars on the PECB website at • https://pecb.com/past-webinars Find all sessions with Q&A + collaterals (decks, recording) at: http://ffwd2.me/PECB_ISO27001_webinars (short cut to LinkedIN page) Previous sessions
  • 6. After the session, you can find the presentation and recording at • https://pecb.com/past-webinars Reference information + Q&A of this session: https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-2021-compliance- new-peter-geelen-/ This session collaterals
  • 7. Overview Of Privacy & Data Protection (P&DP) What's in a word…
  • 8. Data Privacy Definition Information privacy is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, and the legal and political issues surrounding them.* *https://en.wikipedia.org/wiki/Information_privacy
  • 9. Data Protection GDPR Art. 1.1: "protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data" *https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32016R0679
  • 10. GDPR and privacy GDPR itself does not mention privacy… except a footnote on Directive 2002/58/EC, the eCommunications directive In GDPR, it's about data protection, which means protecting your data. Privacy = "The right to be left alone"
  • 11. Some Stats – UN Conference on Trade & Development
  • 12. Privacy, data protection vs. cybersecurity There is No Privacy and data protection Without Cybersecurity But you can have cybersecurity without the need of privacy or data protection.
  • 13. Privacy & Data Protection vs Enterprise security In many cases • Privacy & data protection is targeted to people, persons and their data • Privacy & data protection is (mostly) not about company or enterprise data (finance, operations, products, services…) BUT Data breaches of company data do have the same impact (so treat and protect them equally)
  • 14. Current Status on P&DP The battle for your personal data and privacy
  • 15. North America - Canada PIPEDA - Personal Information Protection and Electronic Documents Act • Federal Legislation managed by the Office of the Privacy Commissioner of Canada • An individual’s consent must be obtained for the collection, use or disclosure of their personal information; individuals have the right to access their personal information and to challenge any inaccuracies in it. • Personal information can inly be used for the purposes for which it was collected otherwise consent must be obtained again. • Personal information must be appropriately protected. • Applies to private sector organizations in Canada. • Is supplemented by privacy laws at the Provincial level in Canada (e.g., laws in Ontario versus Quebec, etc.). • Data that crosses borders, whether within Canada or internationally, is a concern. • Fines: up to $100,000 CAD
  • 16. North America - Canada Other laws: • CASL – Canada Anti Spam Legislation • Federal law • Requires individual’s expressed or implied consent, depending upon the situation • Requires unsubscribe mechanism • Up to $1 million CAD fine per violation and up to $10 million CAD fine for corporations Each Province/Territory in Canada, has its own privacy and health data protection laws but each aligns with PIPEDA and then augments PIPEDA with regional guidance.
  • 17. North America - Canada Multiple laws and legislations across Canada at the Provincial level.
  • 18. North America - Canada Advice: • Become familiar with both the Federal and Provincial laws and legislations before you assume that you are managing personal data correctly Important: better apply this to any privacy & data protection implementation, not only to USA/CA region.
  • 19. North America - USA E-Sign – Electronic Signatures in Global and National Commerce Act • Describes and validates electronic forms of data including e- signatures HIPAA – Health Insurance Portability and Accountability Act of 1996 • Protects privacy of personal health information • Carries penalties of from $100 USD to $50,000 USD per record violation
  • 20. North America - USA California Consumer Privacy Act • Applies to any organization that does business in California and which has gross revenues in excess of $25 million USD or that has 50,000 or more personal records or that earns ½+ of its revenue from selling personal information • Penalties of from $2,500 to $7,500 USD per violation NY Shield Act • If you hold any personal or private data of any New York resident, this applies to you • Penalties of $5,000 USD or $20 USD per violation up to $250,000 USD Maximum
  • 21. Central and South America Mexico - Federal Law on Personal Data Held by Private Parties (FLPPDPP) • Applies to private sector • Oddly, no need to inform any government body should a breach occur Chile- Law No. 19.628 on the Protection of Private Life 1999 • Under development but will align with international privacy laws and standards Brazil – Law No. 13.709 – General Personal Data Protection Law • Into effect in September 2020 but will be enforced beginning August 2021 • Similar to GDPR with DPO’s required, data breach and transfer requirements, and privacy impact assessments • Established history of enforcement WRT privacy Other Countries in Central and South America have currently implemented, draft or in progress privacy laws with only a few countries/locations in Central & South America and the Caribbean with no privacy laws (oddly, Puerto Rico has none).
  • 22. Europe Type of law (Source: EC) • Regulation • Regulations are legal acts that apply automatically and uniformly to all EU countries as soon as they enter into force, • without needing to be transposed into national law. • They are binding in their entirety on all EU countries. • Directive • Directives require EU countries to achieve a certain result, but leave them free to choose how to do so. EU countries must adopt measures to incorporate them into national law (transpose) in order to achieve the objectives set by the directive.
  • 23. Europe GDPR • Data protection (not privacy) • Regulation • Tuned with national legislation
  • 24. Europe Other legislation that impact privacy & data protection • eCommunications & eCommerce • ePrivacy directive (in review/update) But also • NIS (cybersecurity for public & critical infrastructure) • NIS v2 coming up • CyberAct
  • 25. New and updated Privacy Legislations Keep an eye on…
  • 26. North America - Canada CCPA – Consumer Privacy Protection Act • Enhancement to PIPEDA • Privacy and Data Protection Tribunal is established. • Same acronym as the California Consumer Protection Act (also, CCPA) but aims to be even stronger. • Organizations must maintain a privacy management program; meaningful consent must be obtained; deidentified data is covered; right to erasure; enhanced enforcement. • Private lawsuits for violations are permitted. • Third-party service providers are in scope. • Penalties for non-compliance: up to 3% of global revenue or $10 million CAD OR up to 5% of global revenue or $25 million CAD for serious breaches.
  • 27. Europe GDPR Processing principles • eCommunications & eCommerce • High impact on direct marketing • ePrivacy directive (in review/update) • Aligned with GDPR • High impact on direct marketing • NIS (cybersecurity for public & critical infrastructure) • NIS v2 coming up • CyberAct (Cyber certification, PPT, …)
  • 28. Commonalities between legislations Comparing and understanding the context of the legislations
  • 29. Some Common Features • Privacy officer : Like the GDPR requirement, many privacy laws across the world are looking to have a personal appointed in your organization who is accountable for privacy. • Penalties : As we have seen with GDPR and with HIPAA in the USA, financial penalties for violations of privacy legislation or even for improper breach handling can be costly both in terms of monetary cost as well as reputational impact. • Privacy Program : Privacy legislations are increasingly looking for organizations to have a privacy program in place (e.g., privacy policy(ies), breach management plan, privacy awareness training for staff, etc.). • Breach Management and Notification : It is critical to have a documented data breach management plan that also includes a breach notification process. • Consent : Consent for the collection of personal data that includes a precise description of the planned use for the data is critical. • Note that many privacy or data protection laws include the publishing of data breaches or infractions of the privacy legislation. (“Name and Shame”)
  • 30. North America - Canada CCPA – Consumer Privacy Protection Act • Enhancement to PIPEDA • Privacy and Data Protection Tribunal is established. • Same acronym as the California Consumer Protection Act (also, CCPA) but aims to be even stronger. • Organizations must maintain a privacy management program; meaningful consent must be obtained; deidentified data is covered; right to erasure; enhanced enforcement. • Private lawsuits for violations are permitted. • Third-party service providers are in scope. • Penalties for non-compliance: up to 3% of global revenue or $10 million CAD OR up to 5% of global revenue or $25 million CAD for serious breaches.
  • 31. Europe GDPR Processing principles • Principles (Art. 5) (lawful, fairly, transparent, …) • Lawfulness of processing Art. 6 consent, Contract, legal oblication, vital interest, public interest, legitimate interest
  • 32. Europe GDPR Subject Rights • Conditions for consent (incl. minors/children) • Special categories of data • Rights Right of access Right to rectification Right to be forgotten Right to restrict processing Right to notification Right to data portability Right to object
  • 33. Europe GDPR Obligations - Data controllers & data processors • Data protection by default • Data protection by design • Joint controllers • Record of processing (processing register) • Data breach management (incl. notifications) • Security of processing • DPIA
  • 34. Europe GDPR Obligations - Data controllers & data processors • DPO (data protection officer) Designation (public authoriticy, large scale, sensitive data) Position (independent, advisory, …) Tasks Inform & advice Monitor compliance Cooperate with DPA SoD: NOT responsible/accountable for DC/DP tasks
  • 35. Europe GDPR Fines • Purpose: in each individual case , to be effective, proportionate and dissuasive • Depending the nature, gravity and duration of the infringement infringement 2% or €10M 4% or €20M
  • 36. What is the impact?
  • 37. Europe Data protection authorities in action… a trend. There are various sites that follow up on the GDPR fines For example: • https://www.enforcementtracker.com/ • https://www.coreview.com/blog/alpin-gdpr-fines-list/ • https://www.privacyaffairs.com/gdpr-fines/ • …
  • 38. In general • Powerful subject • Data controllers balancing between • Subject rights • Government • Commercial interest • Cross border impact of legislation GDPR is not only for EU companies or EU citizens
  • 40. Privacy & Data protection is HOT • Driver: Cybercrime/breach impact grows • Commercial impact vs subjects • Existing Social media platforms have difficulties to find the new way of working aligned with regulations • New platforms don't get it always right • Take back privacy Very low level of protection of internet data Free flow of data, now issue…
  • 41. Privacy & Data protection is HOT • Cookies management • Dark patterns ("Accept All", before you find the "configure button") • Cookie psychology • Direct marketing Data brokers position Collection of data vs obligations of transparency Public data vs purpose definitions • Cross border, international impact Data brokers out of reach
  • 42. Privacy & Data protection is HOT And also… • IoT Security impact on P&DP • Camera's • Cars • Toys • …
  • 44. Reference material Collateral references and additional info posted on • https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends- 2021-compliance-new-peter-geelen-/
  • 45. ISO/IEC 27701 Training Courses • ISO/IEC 27701 Foundation 2 Day Course • ISO/IEC 27701 Lead Implementer 5Days Course Exam and certification fees are included in the training price. https://pecb.com/en/education-and-certification-for-individuals/iso- 27701 www.pecb.com/events
  • 47. Ramping up… Relevant PECB Training courses
  • 48. Relevant Training PIMS • PECB ISO 27701 Foundation • PECB ISO 27701 LI • PECB ISO 27701 LA Information Security • PECB ISO 27001 LI • PECB ISO 27001 LA • PECB ISO 27002 LM
  • 49. Relevant Training Data protection • PECB Certified Data protection Officer (GDPR) Privacy • PECB ISO29100 LI
  • 50. Other Relevant Training Incident Management • PECB ISO 27035 LI Risk Management • PECB ISO 27005 LI
  • 51. Check the PECB agenda, select the ISO/IEC 27701 Lead Implementer https://pecb.com/en/partnerEvent/event_schedule_list Training Events For full detailed information about an event click on the ‘View’ button on the right hand side under ‘View full details’. Note: Before applying for any training courses listed below, please make sure you are registered to PECB Training Agenda

Hinweis der Redaktion

  1. Peter
  2. Peter
  3. Check the past webinars on the PECB website at https://pecb.com/past-webinars Find all sessions with Q&A + collaterals (decks, recording) at: http://ffwd2.me/PECB_ISO27001_webinars (short cut to LinkedIN page)
  4. After the session, you can find the presentation and recording at https://pecb.com/past-webinars Reference information + Q&A of this session: https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-2021-compliance-new-peter-geelen-/
  5. Tony
  6. Tony
  7. Peter
  8. Peter
  9. Tony https://unctad.org/page/data-protection-and-privacy-legislation-worldwide
  10. Pete
  11. Peter
  12. https://ec.europa.eu/info/law/law-making-process/types-eu-law_en
  13. https://ec.europa.eu/commission/presscorner/detail/en/QANDA_19_3369 Cyberact: https://ec.europa.eu/digital-single-market/en/news/eu-cybersecurity-act-glance bit.ly/EUCyberAct
  14. Peter
  15. https://ec.europa.eu/info/law/law-making-process/types-eu-law_en
  16. Peter
  17. Peter