SlideShare ist ein Scribd-Unternehmen logo
1 von 22
Downloaden Sie, um offline zu lesen
1
vPrivacy Insight Series - truste.com/insightseries
v
Privacy Shield is Here: What You
Need to Know
July 21, 2016
2
vPrivacy Insight Series - truste.com/insightseries
Today’s Speakers
Chris Babel,
CEO
TRUSTe
Caitlin Fennessy
Senior Policy Advisor
Data Flows and Privacy Team
International Trade Administration
U.S. Department of Commerce
3
vPrivacy Insight Series - truste.com/insightseries
• Welcome & Introductions
• Understanding the Differences between Safe Harbor & Privacy Shield
• How the Department of Commerce will Operate the Program
• Working with Third Party Verification & Dispute Resolution Providers
• Looking Forward
• Q&A
Today’s Agenda
4
vPrivacy Insight Series - truste.com/insightseries
v
Understanding the Differences between
Safe Harbor & Privacy Shield
Caitlin Fennessy, Senior Policy Advisor, Privacy & Data Flows Team,
U.S. Department of Commerce
5
vPrivacy Insight Series - truste.com/insightseries
Understanding the Privacy Shield Framework
What does the Privacy Shield contain?
Privacy Shield Principles
–Requirements to which U.S.-based organizations can make an enforceable
commitment to receive data in compliance with EU data protection laws
Letters Describing Oversight and Enforcement from:
–Secretary of Commerce and Under Secretary for International Trade
–Chairwoman of the Federal Trade Commission
–Secretary of Transportation
Government Access to Data
−Letter from the Secretary of State on the new Privacy Shield Ombudsperson
−Letter concerning safeguards and limitations from the Office of the Director of
National Intelligence
−Letter concerning safeguards and limitations from the Department of Justice
5
6
vPrivacy Insight Series - truste.com/insightseries
Understanding the Privacy Shield Framework
What should your company focus on to come into compliance?
What’s new compared to Safe Harbor
1. New Privacy Protections
Notice requirements
Accountability for onward transfer
Purpose limitation and data retention
Note: Companies should review the Framework in its entirety. These
slides are only meant to highlight certain aspects.
6
7
vPrivacy Insight Series - truste.com/insightseries
Understanding the Privacy Shield Framework
What should your company focus on to come into compliance?
What’s new compared to Safe Harbor
2. Enhanced Complaint Resolution
Response time to EU individuals
Free dispute resolution
Binding arbitration as last-resort option
7
8
vPrivacy Insight Series - truste.com/insightseries
Understanding the Privacy Shield Framework
What should your company focus on to come into compliance?
What’s new compared to Safe Harbor
3. Improved Cooperation and Transparency
Monitoring and dispute resolution requires cooperation with
ITA Privacy Shield Team
Ongoing requirements (if withdraw and maintain data)
Publication of FTC compliance reports (if subject to
enforcement action)
8
9
vPrivacy Insight Series - truste.com/insightseries
v
Caitlin Fennessy, Senior Policy Advisor, Privacy & Data Flows Team,
Department of Commerce
How the Department of Commerce will
Operate the Program
10
vPrivacy Insight Series - truste.com/insightseries
Joining the Privacy Shield Program
How will a company join Privacy Shield?
1. Confirm Your Organization’s Eligibility to Participate
2. Develop a Compliant Privacy Policy
3. Establish an Independent Recourse Mechanism (IRM)
4. Ensure a Verification Mechanism is in place
5. Identify your Privacy Shield Point of Contact
6. Self-certify Using the Privacy Shield Website
7. Reaffirm Self-certification Annually
8. Reply to Inquiries from EU citizens, IRM, Commerce, and/or DPAs
as Required
10
11
vPrivacy Insight Series - truste.com/insightseries
Joining the Privacy Shield Program
ITA Administration: What’s new that matters to you?
Maintenance of the Privacy Shield Website
Verification of Self-Certification Requirements
Monitoring of Compliance
Facilitating Resolution of Complaints Referred by EU DPAs
11
12
vPrivacy Insight Series - truste.com/insightseries
Joining the Privacy Shield Program
FTC Enforcement: What has changed (and what hasn’t)?
Prioritization of DPA Referrals
Enforcement Cooperation
Investigatory Assistance
Publication of FTC Compliance Reports
12
13
vPrivacy Insight Series - truste.com/insightseries
v
Chris Babel, CEO, TRUSTe
Third Party Verification &
Dispute Resolution Providers
14
vPrivacy Insight Series - truste.com/insightseries
•Companies must take steps to verify assertions made around Privacy
Shield compliance are true
•Third party compliance reviews can be used to satisfy this requirement
•Third party reviews must:
–Verify privacy policies are being complied with
–Consumers are informed of how they can file a compliant
• Companies must be able to demonstrate an external review has been
successfully completed annually
–This can be provided by the external compliance review provider
•Companies must retain records of their implementation of the Privacy
Shield Principles and privacy policies
–Records must be provided upon request in context of a Privacy Shield related
investigation
Privacy Practices Verification
15
vPrivacy Insight Series - truste.com/insightseries
•Companies must respond to initial complaint within 45-days
•Alternative mechanism must be in place to address Privacy Shield
related complaints
–Independent Dispute Resolution Provider (IDR) can be used for consumer data
–DPAs must be used for employee data
• Must be provided free of charge to individuals
• Companies must provide information regarding their IDR Provider in
their privacy notice
– Name of the designated provider and how to contact them
–Whether the provider is EU or U.S. based
–That it is available free of charge
•Binding arbitration is available after other mechanisms have been
exhausted
Dispute Resolution
16
vPrivacy Insight Series - truste.com/insightseries
• Make information available to consumers about Privacy Shield and the
IDR Provider’s role under Privacy Shield
–Needs to be accessible from IDR Provider’s website
–Link to the DOC’s Privacy Shield site
–Explanation of how to file a complaint, dispute resolution process and
timeframes, and potential remedies
•Report annually to the DOC regarding number, types, and outcomes of
complaints received, and length of time to resolve.
–Reporting in the aggregate
• IDR Providers must notify DOC of companies that fail to resolve
Privacy Shield related complaints.
New requirements for IDR Providers
17
vPrivacy Insight Series - truste.com/insightseries
Impacts on Business
• Companies face stronger obligations for data transfers
• Increased risk stemming from 3rd party processors, partners,
and vendors
• Privacy Shield language needs to be added to contracts,
and be provided to the DOC upon request
• Companies must respond to disputes faster through
additional channels
• Increased regulatory focus
• Companies must document, maintain records and deliver
reports on their compliance efforts
18
vPrivacy Insight Series - truste.com/insightseries
Levels of Third Party Assistance
18
Verification Assessment
Dispute
Resolution
Dispute Resolution mechanism (non
HR)
✔ ✔ ✔
Dispute Resolution Seal/Button (non
HR)
✔ ✔ ✔
Comprehensive Assessment –
Customer and / or HR Data
✔ ✔
Online Asset Review and Scanning ✔ ✔
Findings Report ✔ ✔
Searchable Audit Trail ✔ ✔
DOC Registration Assistance ✔ ✔
Ongoing Guidance ✔ ✔
Remediation Assistance ✔
Verification Seal ✔
Verification Letter of Attestation ✔
Verification Listing for DOC ✔
19
vPrivacy Insight Series - truste.com/insightseries
v
Caitlin Fennessy, Senior Policy Advisor, Privacy & Data Flows Team,
Department of Commerce
Looking Forward
20
vPrivacy Insight Series - truste.com/insightseries
Looking Forward
The GDPR
European Court of Justice
Cooperation with EU DPAs
20
How was the Framework designed to remain durable?
21
vPrivacy Insight Series - truste.com/insightseries
v
Chris Babel cbabel@truste.com
Contacts
22
vPrivacy Insight Series - truste.com/insightseries
v
Details of our 2016 Summer/Fall Webinar Series are now available. Register
now for our next webinar on August 18 “Brazil & Beyond: Privacy Trends in
Latin America”
See http://www.truste.com/insightseries for the 2016 Privacy Insight Series
and past webinar recordings.
Thank You!

Weitere ähnliche Inhalte

Was ist angesagt?

The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
Ghostery, Inc.
 

Was ist angesagt? (20)

The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to know
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor Replacement
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
Do You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? ArticleDo You Have a Roadmap for EU GDPR Compliance? Article
Do You Have a Roadmap for EU GDPR Compliance? Article
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
Ghostery MCM - May 2016
Ghostery MCM - May 2016Ghostery MCM - May 2016
Ghostery MCM - May 2016
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
GDPR: More reasons for information security
GDPR: More reasons for information securityGDPR: More reasons for information security
GDPR: More reasons for information security
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 

Andere mochten auch

Andere mochten auch (10)

EU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTeEU Privacy Shield - Understanding the New Framework from TRUSTe
EU Privacy Shield - Understanding the New Framework from TRUSTe
 
2015 TRUSTe US Consumer Privacy Confidence Index – Infographic
2015 TRUSTe US Consumer Privacy Confidence Index – Infographic2015 TRUSTe US Consumer Privacy Confidence Index – Infographic
2015 TRUSTe US Consumer Privacy Confidence Index – Infographic
 
How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
How Good Privacy Practices can help prepare for a Data Breach from TRUSTe How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
How Good Privacy Practices can help prepare for a Data Breach from TRUSTe
 
US Consumer Privacy Index 2016 – Infographic from TRUSTe & NCSA
US Consumer Privacy Index 2016 – Infographic from TRUSTe & NCSAUS Consumer Privacy Index 2016 – Infographic from TRUSTe & NCSA
US Consumer Privacy Index 2016 – Infographic from TRUSTe & NCSA
 
Study: The Future of VR, AR and Self-Driving Cars
Study: The Future of VR, AR and Self-Driving CarsStudy: The Future of VR, AR and Self-Driving Cars
Study: The Future of VR, AR and Self-Driving Cars
 
The Physical Interface
The Physical InterfaceThe Physical Interface
The Physical Interface
 
Designing Teams for Emerging Challenges
Designing Teams for Emerging ChallengesDesigning Teams for Emerging Challenges
Designing Teams for Emerging Challenges
 
House of representatives daily program, 13 february 2017
House of representatives daily program, 13 february 2017House of representatives daily program, 13 february 2017
House of representatives daily program, 13 february 2017
 
TEDx Manchester: AI & The Future of Work
TEDx Manchester: AI & The Future of WorkTEDx Manchester: AI & The Future of Work
TEDx Manchester: AI & The Future of Work
 
SANS 20 Critical Security Control 17 Requirements for SSL/TLS Security and Ma...
SANS 20 Critical Security Control 17 Requirements for SSL/TLS Security and Ma...SANS 20 Critical Security Control 17 Requirements for SSL/TLS Security and Ma...
SANS 20 Critical Security Control 17 Requirements for SSL/TLS Security and Ma...
 

Ähnlich wie [Webinar Slides] Privacy Shield is Here – What You Need to Know

Last minute preparations for SFTR: What still needs to be done and are we ready?
Last minute preparations for SFTR: What still needs to be done and are we ready?Last minute preparations for SFTR: What still needs to be done and are we ready?
Last minute preparations for SFTR: What still needs to be done and are we ready?
Leigh Hill
 

Ähnlich wie [Webinar Slides] Privacy Shield is Here – What You Need to Know (20)

Steps to prepare for TRUSTe EU certification
Steps to prepare for TRUSTe EU certificationSteps to prepare for TRUSTe EU certification
Steps to prepare for TRUSTe EU certification
 
Privacy Frameworks: The Foundation for Every Privacy Program
Privacy Frameworks: The Foundation for Every Privacy ProgramPrivacy Frameworks: The Foundation for Every Privacy Program
Privacy Frameworks: The Foundation for Every Privacy Program
 
Feb20 Webinar - Managing Risk and Pain of Vendor Management
Feb20 Webinar - Managing Risk and Pain of Vendor ManagementFeb20 Webinar - Managing Risk and Pain of Vendor Management
Feb20 Webinar - Managing Risk and Pain of Vendor Management
 
EU Privacy Shield Self Certification
EU Privacy Shield Self Certification EU Privacy Shield Self Certification
EU Privacy Shield Self Certification
 
Guide to Prospective European Union - United States Privacy Shield Program
Guide to Prospective European Union - United States Privacy Shield ProgramGuide to Prospective European Union - United States Privacy Shield Program
Guide to Prospective European Union - United States Privacy Shield Program
 
CSID - Data Protection - SXSW 2013
CSID - Data Protection - SXSW 2013CSID - Data Protection - SXSW 2013
CSID - Data Protection - SXSW 2013
 
Remedies and Cooperation: What Have we Learned – R. Damtoft USFTC – 2017 Lati...
Remedies and Cooperation: What Have we Learned – R. Damtoft USFTC – 2017 Lati...Remedies and Cooperation: What Have we Learned – R. Damtoft USFTC – 2017 Lati...
Remedies and Cooperation: What Have we Learned – R. Damtoft USFTC – 2017 Lati...
 
Internet security and privacy issues
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issues
 
Data Privacy: The Hidden Beast within Mergers & Acquisitions
Data Privacy: The Hidden Beast within Mergers & AcquisitionsData Privacy: The Hidden Beast within Mergers & Acquisitions
Data Privacy: The Hidden Beast within Mergers & Acquisitions
 
D&B onboard.pdf
D&B onboard.pdfD&B onboard.pdf
D&B onboard.pdf
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
Last minute preparations for SFTR: What still needs to be done and are we ready?
Last minute preparations for SFTR: What still needs to be done and are we ready?Last minute preparations for SFTR: What still needs to be done and are we ready?
Last minute preparations for SFTR: What still needs to be done and are we ready?
 
Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19 Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19
 
Supplier Assurance During COVID-19
Supplier Assurance During COVID-19Supplier Assurance During COVID-19
Supplier Assurance During COVID-19
 
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
Building Your DPIA/PIA Program: Tips & Case Studies [TrustArc Webinar Slides]
 
How Confused.com and iovation Fight Ghost Broking
How Confused.com and iovation Fight Ghost BrokingHow Confused.com and iovation Fight Ghost Broking
How Confused.com and iovation Fight Ghost Broking
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
 
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
Getting to Accountability Karbaliotis and Patrikios-Oct 22 2015
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation Checklist
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection RegulationImplementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation
 

Mehr von TrustArc

TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
TrustArc
 

Mehr von TrustArc (20)

TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 

Kürzlich hochgeladen

一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
bd2c5966a56d
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
ss
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
Airst S
 
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
Fir La
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
F La
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
Airst S
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
bd2c5966a56d
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
F La
 
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
e9733fc35af6
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
JosephCanama
 

Kürzlich hochgeladen (20)

Reason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in IndiaReason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in India
 
Career As Legal Reporters for Law Students
Career As Legal Reporters for Law StudentsCareer As Legal Reporters for Law Students
Career As Legal Reporters for Law Students
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statute
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
 
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptxAnalysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
Analysis of R V Kelkar's Criminal Procedure Code ppt- chapter 1 .pptx
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理一比一原版埃克塞特大学毕业证如何办理
一比一原版埃克塞特大学毕业证如何办理
 
Navigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptxNavigating Employment Law - Term Project.pptx
Navigating Employment Law - Term Project.pptx
 
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
一比一原版(IC毕业证书)帝国理工学院毕业证如何办理
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in Law
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
 
一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理一比一原版伦敦南岸大学毕业证如何办理
一比一原版伦敦南岸大学毕业证如何办理
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
 
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
一比一原版(Waterloo毕业证书)加拿大滑铁卢大学毕业证如何办理
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 

[Webinar Slides] Privacy Shield is Here – What You Need to Know

  • 1. 1 vPrivacy Insight Series - truste.com/insightseries v Privacy Shield is Here: What You Need to Know July 21, 2016
  • 2. 2 vPrivacy Insight Series - truste.com/insightseries Today’s Speakers Chris Babel, CEO TRUSTe Caitlin Fennessy Senior Policy Advisor Data Flows and Privacy Team International Trade Administration U.S. Department of Commerce
  • 3. 3 vPrivacy Insight Series - truste.com/insightseries • Welcome & Introductions • Understanding the Differences between Safe Harbor & Privacy Shield • How the Department of Commerce will Operate the Program • Working with Third Party Verification & Dispute Resolution Providers • Looking Forward • Q&A Today’s Agenda
  • 4. 4 vPrivacy Insight Series - truste.com/insightseries v Understanding the Differences between Safe Harbor & Privacy Shield Caitlin Fennessy, Senior Policy Advisor, Privacy & Data Flows Team, U.S. Department of Commerce
  • 5. 5 vPrivacy Insight Series - truste.com/insightseries Understanding the Privacy Shield Framework What does the Privacy Shield contain? Privacy Shield Principles –Requirements to which U.S.-based organizations can make an enforceable commitment to receive data in compliance with EU data protection laws Letters Describing Oversight and Enforcement from: –Secretary of Commerce and Under Secretary for International Trade –Chairwoman of the Federal Trade Commission –Secretary of Transportation Government Access to Data −Letter from the Secretary of State on the new Privacy Shield Ombudsperson −Letter concerning safeguards and limitations from the Office of the Director of National Intelligence −Letter concerning safeguards and limitations from the Department of Justice 5
  • 6. 6 vPrivacy Insight Series - truste.com/insightseries Understanding the Privacy Shield Framework What should your company focus on to come into compliance? What’s new compared to Safe Harbor 1. New Privacy Protections Notice requirements Accountability for onward transfer Purpose limitation and data retention Note: Companies should review the Framework in its entirety. These slides are only meant to highlight certain aspects. 6
  • 7. 7 vPrivacy Insight Series - truste.com/insightseries Understanding the Privacy Shield Framework What should your company focus on to come into compliance? What’s new compared to Safe Harbor 2. Enhanced Complaint Resolution Response time to EU individuals Free dispute resolution Binding arbitration as last-resort option 7
  • 8. 8 vPrivacy Insight Series - truste.com/insightseries Understanding the Privacy Shield Framework What should your company focus on to come into compliance? What’s new compared to Safe Harbor 3. Improved Cooperation and Transparency Monitoring and dispute resolution requires cooperation with ITA Privacy Shield Team Ongoing requirements (if withdraw and maintain data) Publication of FTC compliance reports (if subject to enforcement action) 8
  • 9. 9 vPrivacy Insight Series - truste.com/insightseries v Caitlin Fennessy, Senior Policy Advisor, Privacy & Data Flows Team, Department of Commerce How the Department of Commerce will Operate the Program
  • 10. 10 vPrivacy Insight Series - truste.com/insightseries Joining the Privacy Shield Program How will a company join Privacy Shield? 1. Confirm Your Organization’s Eligibility to Participate 2. Develop a Compliant Privacy Policy 3. Establish an Independent Recourse Mechanism (IRM) 4. Ensure a Verification Mechanism is in place 5. Identify your Privacy Shield Point of Contact 6. Self-certify Using the Privacy Shield Website 7. Reaffirm Self-certification Annually 8. Reply to Inquiries from EU citizens, IRM, Commerce, and/or DPAs as Required 10
  • 11. 11 vPrivacy Insight Series - truste.com/insightseries Joining the Privacy Shield Program ITA Administration: What’s new that matters to you? Maintenance of the Privacy Shield Website Verification of Self-Certification Requirements Monitoring of Compliance Facilitating Resolution of Complaints Referred by EU DPAs 11
  • 12. 12 vPrivacy Insight Series - truste.com/insightseries Joining the Privacy Shield Program FTC Enforcement: What has changed (and what hasn’t)? Prioritization of DPA Referrals Enforcement Cooperation Investigatory Assistance Publication of FTC Compliance Reports 12
  • 13. 13 vPrivacy Insight Series - truste.com/insightseries v Chris Babel, CEO, TRUSTe Third Party Verification & Dispute Resolution Providers
  • 14. 14 vPrivacy Insight Series - truste.com/insightseries •Companies must take steps to verify assertions made around Privacy Shield compliance are true •Third party compliance reviews can be used to satisfy this requirement •Third party reviews must: –Verify privacy policies are being complied with –Consumers are informed of how they can file a compliant • Companies must be able to demonstrate an external review has been successfully completed annually –This can be provided by the external compliance review provider •Companies must retain records of their implementation of the Privacy Shield Principles and privacy policies –Records must be provided upon request in context of a Privacy Shield related investigation Privacy Practices Verification
  • 15. 15 vPrivacy Insight Series - truste.com/insightseries •Companies must respond to initial complaint within 45-days •Alternative mechanism must be in place to address Privacy Shield related complaints –Independent Dispute Resolution Provider (IDR) can be used for consumer data –DPAs must be used for employee data • Must be provided free of charge to individuals • Companies must provide information regarding their IDR Provider in their privacy notice – Name of the designated provider and how to contact them –Whether the provider is EU or U.S. based –That it is available free of charge •Binding arbitration is available after other mechanisms have been exhausted Dispute Resolution
  • 16. 16 vPrivacy Insight Series - truste.com/insightseries • Make information available to consumers about Privacy Shield and the IDR Provider’s role under Privacy Shield –Needs to be accessible from IDR Provider’s website –Link to the DOC’s Privacy Shield site –Explanation of how to file a complaint, dispute resolution process and timeframes, and potential remedies •Report annually to the DOC regarding number, types, and outcomes of complaints received, and length of time to resolve. –Reporting in the aggregate • IDR Providers must notify DOC of companies that fail to resolve Privacy Shield related complaints. New requirements for IDR Providers
  • 17. 17 vPrivacy Insight Series - truste.com/insightseries Impacts on Business • Companies face stronger obligations for data transfers • Increased risk stemming from 3rd party processors, partners, and vendors • Privacy Shield language needs to be added to contracts, and be provided to the DOC upon request • Companies must respond to disputes faster through additional channels • Increased regulatory focus • Companies must document, maintain records and deliver reports on their compliance efforts
  • 18. 18 vPrivacy Insight Series - truste.com/insightseries Levels of Third Party Assistance 18 Verification Assessment Dispute Resolution Dispute Resolution mechanism (non HR) ✔ ✔ ✔ Dispute Resolution Seal/Button (non HR) ✔ ✔ ✔ Comprehensive Assessment – Customer and / or HR Data ✔ ✔ Online Asset Review and Scanning ✔ ✔ Findings Report ✔ ✔ Searchable Audit Trail ✔ ✔ DOC Registration Assistance ✔ ✔ Ongoing Guidance ✔ ✔ Remediation Assistance ✔ Verification Seal ✔ Verification Letter of Attestation ✔ Verification Listing for DOC ✔
  • 19. 19 vPrivacy Insight Series - truste.com/insightseries v Caitlin Fennessy, Senior Policy Advisor, Privacy & Data Flows Team, Department of Commerce Looking Forward
  • 20. 20 vPrivacy Insight Series - truste.com/insightseries Looking Forward The GDPR European Court of Justice Cooperation with EU DPAs 20 How was the Framework designed to remain durable?
  • 21. 21 vPrivacy Insight Series - truste.com/insightseries v Chris Babel cbabel@truste.com Contacts
  • 22. 22 vPrivacy Insight Series - truste.com/insightseries v Details of our 2016 Summer/Fall Webinar Series are now available. Register now for our next webinar on August 18 “Brazil & Beyond: Privacy Trends in Latin America” See http://www.truste.com/insightseries for the 2016 Privacy Insight Series and past webinar recordings. Thank You!