SlideShare ist ein Scribd-Unternehmen logo
1 von 11
Copyright © 2018 Accenture. All rights reserved. 1
GDPRDATA PRIVACY
IN THE NEW
Copyright © 2018 Accenture. All rights reserved. 2
GDPR harmonizes a
series of complex
European data protection
requirements and
codifies new privacy
rights and protections for
EU citizens.
GDPR’S INTENT: CODIFY RIGHTS AND GIVE PEOPLE
POWER OVER THEIR INFORMATION
Key GDPR Requirements
Data Subject Rights
Can you completely erase
personal data
when needed?
Privacy by Design
Are your products and
services privacy friendly?
Accountability
Are you confident the
third parties you use
will be compliant?
Consent
Have you collected and
documented consent for
every data use?
Breach
Notification
Can you quickly
recognize and report
a data breach?
GENERAL DATA PROTECTION REGULATION
SCOPE WIDENED STRONGER ENFORCEMENT &
ACCOUNTABILITY
INDIVIDUAL’S RIGHTS INCREASEDHARMONIZATION ACROSS EU
Protect personally identifiable data of EU citizens, wherever it is possible
New: Significant amendments and new obligations. Individuals have new rights to object to
profiling, to be forgotten and for data portability.
GDPR has come
into effect
The final text of the
GDPR was published
The EU Parliament approved the
final text in its plenary session
TIMELINE
 Right to be forgotten, to erasure, to data
portability, to rectification, to restriction of
processing, of access by the data subject, to
object
 Notification obligation for data breaches
 Unambiguous consent required for data
usage
2015 2019
Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2
15.12.2015 25.05.201814.04.2016
IMPACT/CHANGES
 Fines for violations can be 4% of global
turnover (revenue), or €20 million
(whichever is higher)
 Data protection officer to be appointed
 Privacy by Design
 Data Protection Authority assessment &
approval
 Culture of internal monitoring & reviewing
 Harmonized rules - unified legal
landscape
 Overseen by a European Data Privacy
Board plus local regulators
 Territorial scope in EU & EU data
subjects, regardless of where data
controller / processor located
 Special rules for sensitive data such as
health, biometric, ethnic data, etc., and for
data concerning criminal convictions and
offenses
 Data controller vs. processor:
accountability for 3rd party processors
DRIVERS
 Data breaches: increasing amount led to concerns for customers and regulators
 Regulatory changes: new rights for individuals - right to be forgotten, portability, breach
notification
 Lack of harmonization of privacy regulation in EU: GDPR to harmonize privacy
legislation among EU member states
THEEUGENERALDATAPROTECTIONREGULATION
2016 2018
Ongoing compliance activities and
continuous improvement
Copyright © 2018 Accenture. All rights reserved.
Accenture analysis based upon publicly available documents.
WHAT CONCERNS DO ORGANIZATIONS HAVE?
46%
of companies surveyed are
concerned about FINES
33%
of companies surveyed are concerned about
the NEED TO INFORM CUSTOMERS
OF DATA BREACHES within 72hrs.
31%
of companies surveyed are concerned
about the VOLUME OF DATA STORE
they need to protect
Source: “EU General Data Protection Regulation Survey,” Boldonjames.com. Access at:
https://www.boldonjames.com/resources/eu-data-protection-regulation-survey-infographic/.
36%
of companies surveyed believe changing
processes around DATA PROTECTION and
MANAGEMENT is the biggest challenge
4
Copyright © 2018 Accenture. All rights reserved.
Accenture’s research into consumer
behavior suggests data privacy and
protection is not just about compliance
and should be at the core of wider
business strategy.
8out of 10
surveyed consumers say trust is a
key driver of brand loyalty†
Consumers surveyed would consider
asking their financial services provider
to delete personal data,
About 2
out of 3
††
4 out of 10
consumers surveyed, trust in a
company increases when breaches are
handled swiftly and correctly†
of UK consumers surveyed are willing to
share their personal information with their
bank in return for certain added benefits and
more personalized, relevant services
54%††
† A New Slice of PI, with a Side of Digital Trust, Accenture 2017.
† † UK Financial Services Customer Survey 2018, Accenture 2018.
Copyright © 2018 Accenture. All rights reserved. 5
REGULATORY CONTEXT AND INDUSTRY CHALLENGES
GDPR COMPLIANCE IS FAR FROM BEING A SINGLE ONE-OFF REMEDIATION EFFORT AND MOST
ORGANIZATIONS MAY NOT BE FULLY COMPLIANT BY 25TH MAY, 2018
2018
ACHIEVE “DEFENSIBLE”
COMPLIANCE POSITION
BASED ON RISK APPETITE
IMPLEMENT GDPR
MEASURES TO
MITIGATE “RESIDUAL
RISKS”
STATEGIC GDPR
DIFFERENTIATION
 Implement data deletion and
security measures for
medium - low risk areas
 Improve data governance
and data discovery
 Improve third party due-
diligence / risk management
 Increase customer trust by
improving privacy controls
and culture
 Help reduce cost of data
operations
 Leverage data as a
strategic differentiator
 Reduce third-party supplier
risk
 Implement new GDPR
Governance Model
 Implement new subject rights
and consent framework
 Implement data deletion and
security measures for high risk
areas
2019
MARKET INSIGHTS
MAY
High Impact: GDPR is a complex
game with high impact on Systems
Risk-Based Approach: Clients’
GDPR is too big to be totally
completed by 2018 – primary focus
should be on the highest risk areas
with an intent to cover in a second
step the remaining ones
Different actions according to
Maturity Level: The action plan is
linked to the maturity level / state of
art of the Privacy Framework /
existing solutions / projects
Users have the right to be
forgotten; data should be
erased on request
Organizations have to
notify authorities of data
breaches
Personal data is portable,
and can be transferred on
request
Organizations handling
personal data have to
assign a data protection
officer
A user should be able to easily
withdraw, and give informed
data collection consent
Security / Privacy by design; for
solutions and processes related to
handling / collecting of personal data,
privacy and security should be prioritized
Organizationscanbeauditedtoprovetheir
compliancewithGDPR
Organizations have to follow
the data minimization
principle; only collect data
which is directly relevant and
necessary to accomplish a
specified purpose
OPERATIONAL THEMES TO BECOME GDPR READY
All data should be adequately
protected and consent
secured
6Copyright © 2018 Accenture. All rights reserved.
Copyright © 2018 Accenture. All rights reserved. 7
OPPORTUNITIES AND CONSIDERATIONS FOR THE FUTURE
GDPR impacts
across businesses,
thus requires a
cross-functional
team
It is not just a Risk, IT,
Security or legal project –
business involvement is key
1
Ensure you
understand
accountability of
data controllers
This is more than just a name
in the frame, it is about where
it may be funded from and
who has influence to make
the change happen across
the organization
6
Customer journey
led discovery
Identify the top 5-10 customer
journeys, they may often
drive out the biggest risks like
data movement across Utility
entities and across systems
and prioritize remediation
accordingly
2
Embed the Data
Protection Officer
(DPO) in the
organization
Ensure that the DPO has the
right capabilities (skills, team,
authority) and is empowered
to highlight risks and make
changes happen
7
Prioritize on risks
and demonstrate
change
In many ways GDPR might
be too big to be totally
completed by 2018 – focus
on the highest risks first with
an intent to cover all areas
3
Alliance and
partners are your
responsibility
You are now accountable for
your alliance / partners being
Data Processors and these
are often obscure e.g. cloud
providers
4
Assess existing
projects to scale
Data privacy should be a part
of all data-related projects,
not just a one-time dedicated
program
5
Different parts of
the organization
can be different in
maturity
It’s natural for some areas to
be further ahead, use the
wins of leading parts of the
organization and make sure
all areas are coordinated
8
Tools and
organizational
experience are
critical
There is no silver bullet to
GDPR compliance. There
should be no substitute for
engaging stakeholders
around the enterprise to
understand the hidden
nuances in getting to a
compliant position
9
From burden to
opportunity
GDPR investment can be
leveraged to drive business
value and opportunities e.g.
establishing simpler data
operations and potentially
reduce the cost and data
noise
10
FROM BURDEN TO OPPORTUNITY
A defined customer data strategy may help companies to turn regulatory burden and
challenges into a competitive advantage.
Stricter consent
Detailed records on data use
New categories of personal data
Stricter governance
Data privacy by design
Accountability for 3rd party
sharing
Minimization of customer data
Right to be forgotten
Improve marketing opt-in
More efficient data operations
More comprehensive profiles
Value-based data investments
Improved ROI of new initiatives
More value from data sharing
Potential reduction of cost and
data noise
Improved marketing spend
Enhance consent model /Value exchange
Enterprise-wide customer data mapping
Treat digital shadow as customer data
Put customer data into business ownership
Business cases with value / risk of customer data
Define 3rd party data sharing strategy
Cleanse data lakes from no-value records
Stop targeting customers that are not interested
From Burden... ...to Opportunity
8Copyright © 2018 Accenture. All rights reserved.
Copyright © 2018 Accenture. All rights reserved. 9
PRIVACY ACT – WHAT’S THE BILL GOING TO DO?
Personal Info Collected
Personal Information Sold
Right to Say No
The California Consumer Privacy Act of 2018 is going to put safeguards in place to further project consumers privacy. If enacted the bill will govern the
way a consumer’s personal information is being received, held and shared with businesses. The bill has severe implications to businesses that handle or
share consumer(s) information. The 8 sections outlined below are components of the bill and will cover how Personal Information (PI) should be handled.
2
3
Equal Service and Price
Disclosure Requirements
Notice Requirements
5
6
4
Clarifying Definitions
Exemptions
7
1
8
Biometric
data Personal
identifiers like
real name,
alias, account
name, etc.
Audio,
electronic,
visual, thermal
Inferences to
any PI info
Any PI related
to children of
consumer
Internet or
network
activity info
Psychometric
Info
Geolocation
data
Records of
property, products
or services
provided
Professional or
employment-
related info
Examples of
Personal
Information
Accenture analysis based upon publicly available documents.
Copyright © 2018 Accenture. All rights reserved. 10
ACCENTURE CONTACT INFORMATION
Lisa Bloomberg
Principal Director
Financial Services
Regulatory & Compliance
New York
Lisa.Bloomberg@Accenture.com
Tel: +1 917-452-6247
Chris Beck
Senior Manager
Financial Services
Regulatory & Compliance
Chicago
Christoper.t.beck@Accenture.com
Tel: +1 312-693-6246
Samantha Regan
Managing Director
Financial Services Regulatory &
Compliance Management Lead
for North America
samantha.regan@accenture.com
Tel: +1 404-790-7378
Ben Shorten
Senior Manager
Financial Services
Regulatory & Compliance
New York
benjamin.j.shorten@accenture.com
Tel: +1 (512) 739 4080
Daniel J. Maloney
Senior Manager
Regulatory & Compliance
Charlotte
Daniel.Maloney@Accenture.com
Tel: +1 908-489-4602
Copyright © 2018 Accenture. All rights reserved. 11
GDPR
DATA PRIVACY IN THE NEW
About Accenture
Accenture is a leading global professional services
company, providing a broad range of services and
solutions in strategy, consulting, digital, technology and
operations. Combining unmatched experience and
specialized skills across more than 40 industries and all
business functions—underpinned by the world’s largest
delivery network—Accenture works at the intersection of
business and technology to help clients improve their
performance and create sustainable value for their
stakeholders. With more than 442,000 people serving
clients in more than 120 countries, Accenture drives
innovation to improve the way the world works and lives.
Visit us at www.accenture.com
Accenture, its logo, and High Performance Delivered are
trademarks of Accenture.
Disclaimer
This presentation is intended for general informational
purposes only and does not take into account the
reader’s specific circumstances, and may not reflect the
most current developments. Accenture disclaims, to the
fullest extent permitted by applicable law, any and all
liability for the accuracy and completeness of the
information in this presentation and for any acts or
omissions made based on such information. Accenture
does not provide legal, regulatory, audit, or tax
advice. Readers are responsible for obtaining such
advice from their own legal counsel or other licensed
professionals.

Weitere ähnliche Inhalte

Was ist angesagt?

Organizing Master Data Management
Organizing Master Data ManagementOrganizing Master Data Management
Organizing Master Data ManagementBoris Otto
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
Data Modeling, Data Governance, & Data Quality
Data Modeling, Data Governance, & Data QualityData Modeling, Data Governance, & Data Quality
Data Modeling, Data Governance, & Data QualityDATAVERSITY
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Building an Effective Data & Analytics Operating Model A Data Modernization G...
Building an Effective Data & Analytics Operating Model A Data Modernization G...Building an Effective Data & Analytics Operating Model A Data Modernization G...
Building an Effective Data & Analytics Operating Model A Data Modernization G...Mark Hewitt
 
Building a Data Governance Strategy
Building a Data Governance StrategyBuilding a Data Governance Strategy
Building a Data Governance StrategyAnalytics8
 
Data Management Maturity Assessment
Data Management Maturity AssessmentData Management Maturity Assessment
Data Management Maturity AssessmentFiras Hamdan
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRIT Governance Ltd
 
Master Data Management – Aligning Data, Process, and Governance
Master Data Management – Aligning Data, Process, and GovernanceMaster Data Management – Aligning Data, Process, and Governance
Master Data Management – Aligning Data, Process, and GovernanceDATAVERSITY
 
Data Audit Approach To Developing An Enterprise Data Strategy
Data Audit Approach To Developing An Enterprise Data StrategyData Audit Approach To Developing An Enterprise Data Strategy
Data Audit Approach To Developing An Enterprise Data StrategyAlan McSweeney
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law Owako Rodah
 
[Webinar Slides] Developing a Successful Data Retention Policy
[Webinar Slides] Developing a Successful Data Retention Policy [Webinar Slides] Developing a Successful Data Retention Policy
[Webinar Slides] Developing a Successful Data Retention Policy AIIM International
 
CIPPE_SampleQuestions_v6.0.pdf
CIPPE_SampleQuestions_v6.0.pdfCIPPE_SampleQuestions_v6.0.pdf
CIPPE_SampleQuestions_v6.0.pdfDusanPavlovic12
 
Data Governance Best Practices
Data Governance Best PracticesData Governance Best Practices
Data Governance Best PracticesBoris Otto
 

Was ist angesagt? (20)

Organizing Master Data Management
Organizing Master Data ManagementOrganizing Master Data Management
Organizing Master Data Management
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Data Modeling, Data Governance, & Data Quality
Data Modeling, Data Governance, & Data QualityData Modeling, Data Governance, & Data Quality
Data Modeling, Data Governance, & Data Quality
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Building an Effective Data & Analytics Operating Model A Data Modernization G...
Building an Effective Data & Analytics Operating Model A Data Modernization G...Building an Effective Data & Analytics Operating Model A Data Modernization G...
Building an Effective Data & Analytics Operating Model A Data Modernization G...
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
Building a Data Governance Strategy
Building a Data Governance StrategyBuilding a Data Governance Strategy
Building a Data Governance Strategy
 
Data Management Maturity Assessment
Data Management Maturity AssessmentData Management Maturity Assessment
Data Management Maturity Assessment
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
DMBOK and Data Governance
DMBOK and Data GovernanceDMBOK and Data Governance
DMBOK and Data Governance
 
Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
 
Master Data Management – Aligning Data, Process, and Governance
Master Data Management – Aligning Data, Process, and GovernanceMaster Data Management – Aligning Data, Process, and Governance
Master Data Management – Aligning Data, Process, and Governance
 
Data Audit Approach To Developing An Enterprise Data Strategy
Data Audit Approach To Developing An Enterprise Data StrategyData Audit Approach To Developing An Enterprise Data Strategy
Data Audit Approach To Developing An Enterprise Data Strategy
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law
 
[Webinar Slides] Developing a Successful Data Retention Policy
[Webinar Slides] Developing a Successful Data Retention Policy [Webinar Slides] Developing a Successful Data Retention Policy
[Webinar Slides] Developing a Successful Data Retention Policy
 
CIPPE_SampleQuestions_v6.0.pdf
CIPPE_SampleQuestions_v6.0.pdfCIPPE_SampleQuestions_v6.0.pdf
CIPPE_SampleQuestions_v6.0.pdf
 
Data Governance Best Practices
Data Governance Best PracticesData Governance Best Practices
Data Governance Best Practices
 

Ähnlich wie GDPR: Data Privacy in the New

GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadVisitor Analytics
 
Security, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightSecurity, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightN-iX
 
Looking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance DeadlineLooking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance Deadlineaccenture
 
Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020TheCEOViews
 
Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Sean Bailey
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...eHealth Forum
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
Data Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxData Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxAdarsh748147
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowIntegrate
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementHow GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementRay Business Technologies
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.Steven Salter
 
Data opportunities mini whitepaper
Data opportunities mini whitepaperData opportunities mini whitepaper
Data opportunities mini whitepaperRobert Bowstead
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
What is data protection and why it is important for business
What is data protection and why it is important for businessWhat is data protection and why it is important for business
What is data protection and why it is important for businessSameerShaik43
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessSirius
 

Ähnlich wie GDPR: Data Privacy in the New (20)

GDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free DownloadGDPR & Data Privacy Guide - Free Download
GDPR & Data Privacy Guide - Free Download
 
Security, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it rightSecurity, GDRP, and IT outsourcing: How to get it right
Security, GDRP, and IT outsourcing: How to get it right
 
Looking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance DeadlineLooking Beyond GDPR Compliance Deadline
Looking Beyond GDPR Compliance Deadline
 
Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020Top 10 GDPR solution providers 2020
Top 10 GDPR solution providers 2020
 
Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit Janrain Identity Cloud GDPR Assessment Kit
Janrain Identity Cloud GDPR Assessment Kit
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
Data Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxData Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptx
 
Are you GDPRed yet?
Are you GDPRed yet?Are you GDPRed yet?
Are you GDPRed yet?
 
Preparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must KnowPreparing for GDPR: What Every B2B Marketer Must Know
Preparing for GDPR: What Every B2B Marketer Must Know
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer EngagementHow GDPR Guidelines Regulate Marketing Automation and Customer Engagement
How GDPR Guidelines Regulate Marketing Automation and Customer Engagement
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.GDPR: A Threat or Opportunity? www.normanbroadbent.
GDPR: A Threat or Opportunity? www.normanbroadbent.
 
Data opportunities mini whitepaper
Data opportunities mini whitepaperData opportunities mini whitepaper
Data opportunities mini whitepaper
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
What is data protection and why it is important for business
What is data protection and why it is important for businessWhat is data protection and why it is important for business
What is data protection and why it is important for business
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 

Mehr von accenture

The Industrialist: Trends & Innovations - January 2024
The Industrialist: Trends & Innovations - January 2024The Industrialist: Trends & Innovations - January 2024
The Industrialist: Trends & Innovations - January 2024accenture
 
The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023accenture
 
Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education accenture
 
The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023accenture
 
Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education accenture
 
Engineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibileEngineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibileaccenture
 
Digital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial SystemDigital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial Systemaccenture
 
More deals, less money: the Black founder funding journey
More deals, less money: the Black founder funding journeyMore deals, less money: the Black founder funding journey
More deals, less money: the Black founder funding journeyaccenture
 
The Industrialist: Trends & Innovations - June 2023
The Industrialist: Trends & Innovations - June 2023The Industrialist: Trends & Innovations - June 2023
The Industrialist: Trends & Innovations - June 2023accenture
 
Reinventing Enterprise Operations
Reinventing Enterprise OperationsReinventing Enterprise Operations
Reinventing Enterprise Operationsaccenture
 
Semiconductor Gender Parity Study
Semiconductor Gender Parity StudySemiconductor Gender Parity Study
Semiconductor Gender Parity Studyaccenture
 
The Industrialist: Trends & Innovations - March 2023
The Industrialist: Trends & Innovations - March 2023The Industrialist: Trends & Innovations - March 2023
The Industrialist: Trends & Innovations - March 2023accenture
 
Nonprofit reinvention in a time of unprecedented change
 Nonprofit reinvention in a time of unprecedented change Nonprofit reinvention in a time of unprecedented change
Nonprofit reinvention in a time of unprecedented changeaccenture
 
Free to be 100% me
Free to be 100% meFree to be 100% me
Free to be 100% meaccenture
 
The Industrialist: Trends & Innovations - February 2023
The Industrialist: Trends & Innovations - February 2023The Industrialist: Trends & Innovations - February 2023
The Industrialist: Trends & Innovations - February 2023accenture
 
Mundo gamer e a oportunidade de entrada pela abordagem do movimento
Mundo gamer e a oportunidade de entrada pela abordagem do movimentoMundo gamer e a oportunidade de entrada pela abordagem do movimento
Mundo gamer e a oportunidade de entrada pela abordagem do movimentoaccenture
 
Pathways to Profitability for the Communications Industry
Pathways to Profitability for the Communications IndustryPathways to Profitability for the Communications Industry
Pathways to Profitability for the Communications Industryaccenture
 
The Industrialist: Trends & Innovations - January 2023
The Industrialist: Trends & Innovations - January 2023The Industrialist: Trends & Innovations - January 2023
The Industrialist: Trends & Innovations - January 2023accenture
 
Reimagining the Agenda | Accenture
Reimagining the Agenda | AccentureReimagining the Agenda | Accenture
Reimagining the Agenda | Accentureaccenture
 
Climate Leadership Eleventh Hour | Accenture
Climate Leadership Eleventh Hour | AccentureClimate Leadership Eleventh Hour | Accenture
Climate Leadership Eleventh Hour | Accentureaccenture
 

Mehr von accenture (20)

The Industrialist: Trends & Innovations - January 2024
The Industrialist: Trends & Innovations - January 2024The Industrialist: Trends & Innovations - January 2024
The Industrialist: Trends & Innovations - January 2024
 
The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023
 
Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education
 
The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023
 
Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education
 
Engineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibileEngineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibile
 
Digital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial SystemDigital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial System
 
More deals, less money: the Black founder funding journey
More deals, less money: the Black founder funding journeyMore deals, less money: the Black founder funding journey
More deals, less money: the Black founder funding journey
 
The Industrialist: Trends & Innovations - June 2023
The Industrialist: Trends & Innovations - June 2023The Industrialist: Trends & Innovations - June 2023
The Industrialist: Trends & Innovations - June 2023
 
Reinventing Enterprise Operations
Reinventing Enterprise OperationsReinventing Enterprise Operations
Reinventing Enterprise Operations
 
Semiconductor Gender Parity Study
Semiconductor Gender Parity StudySemiconductor Gender Parity Study
Semiconductor Gender Parity Study
 
The Industrialist: Trends & Innovations - March 2023
The Industrialist: Trends & Innovations - March 2023The Industrialist: Trends & Innovations - March 2023
The Industrialist: Trends & Innovations - March 2023
 
Nonprofit reinvention in a time of unprecedented change
 Nonprofit reinvention in a time of unprecedented change Nonprofit reinvention in a time of unprecedented change
Nonprofit reinvention in a time of unprecedented change
 
Free to be 100% me
Free to be 100% meFree to be 100% me
Free to be 100% me
 
The Industrialist: Trends & Innovations - February 2023
The Industrialist: Trends & Innovations - February 2023The Industrialist: Trends & Innovations - February 2023
The Industrialist: Trends & Innovations - February 2023
 
Mundo gamer e a oportunidade de entrada pela abordagem do movimento
Mundo gamer e a oportunidade de entrada pela abordagem do movimentoMundo gamer e a oportunidade de entrada pela abordagem do movimento
Mundo gamer e a oportunidade de entrada pela abordagem do movimento
 
Pathways to Profitability for the Communications Industry
Pathways to Profitability for the Communications IndustryPathways to Profitability for the Communications Industry
Pathways to Profitability for the Communications Industry
 
The Industrialist: Trends & Innovations - January 2023
The Industrialist: Trends & Innovations - January 2023The Industrialist: Trends & Innovations - January 2023
The Industrialist: Trends & Innovations - January 2023
 
Reimagining the Agenda | Accenture
Reimagining the Agenda | AccentureReimagining the Agenda | Accenture
Reimagining the Agenda | Accenture
 
Climate Leadership Eleventh Hour | Accenture
Climate Leadership Eleventh Hour | AccentureClimate Leadership Eleventh Hour | Accenture
Climate Leadership Eleventh Hour | Accenture
 

Kürzlich hochgeladen

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 

Kürzlich hochgeladen (20)

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 

GDPR: Data Privacy in the New

  • 1. Copyright © 2018 Accenture. All rights reserved. 1 GDPRDATA PRIVACY IN THE NEW
  • 2. Copyright © 2018 Accenture. All rights reserved. 2 GDPR harmonizes a series of complex European data protection requirements and codifies new privacy rights and protections for EU citizens. GDPR’S INTENT: CODIFY RIGHTS AND GIVE PEOPLE POWER OVER THEIR INFORMATION Key GDPR Requirements Data Subject Rights Can you completely erase personal data when needed? Privacy by Design Are your products and services privacy friendly? Accountability Are you confident the third parties you use will be compliant? Consent Have you collected and documented consent for every data use? Breach Notification Can you quickly recognize and report a data breach?
  • 3. GENERAL DATA PROTECTION REGULATION SCOPE WIDENED STRONGER ENFORCEMENT & ACCOUNTABILITY INDIVIDUAL’S RIGHTS INCREASEDHARMONIZATION ACROSS EU Protect personally identifiable data of EU citizens, wherever it is possible New: Significant amendments and new obligations. Individuals have new rights to object to profiling, to be forgotten and for data portability. GDPR has come into effect The final text of the GDPR was published The EU Parliament approved the final text in its plenary session TIMELINE  Right to be forgotten, to erasure, to data portability, to rectification, to restriction of processing, of access by the data subject, to object  Notification obligation for data breaches  Unambiguous consent required for data usage 2015 2019 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 15.12.2015 25.05.201814.04.2016 IMPACT/CHANGES  Fines for violations can be 4% of global turnover (revenue), or €20 million (whichever is higher)  Data protection officer to be appointed  Privacy by Design  Data Protection Authority assessment & approval  Culture of internal monitoring & reviewing  Harmonized rules - unified legal landscape  Overseen by a European Data Privacy Board plus local regulators  Territorial scope in EU & EU data subjects, regardless of where data controller / processor located  Special rules for sensitive data such as health, biometric, ethnic data, etc., and for data concerning criminal convictions and offenses  Data controller vs. processor: accountability for 3rd party processors DRIVERS  Data breaches: increasing amount led to concerns for customers and regulators  Regulatory changes: new rights for individuals - right to be forgotten, portability, breach notification  Lack of harmonization of privacy regulation in EU: GDPR to harmonize privacy legislation among EU member states THEEUGENERALDATAPROTECTIONREGULATION 2016 2018 Ongoing compliance activities and continuous improvement Copyright © 2018 Accenture. All rights reserved. Accenture analysis based upon publicly available documents.
  • 4. WHAT CONCERNS DO ORGANIZATIONS HAVE? 46% of companies surveyed are concerned about FINES 33% of companies surveyed are concerned about the NEED TO INFORM CUSTOMERS OF DATA BREACHES within 72hrs. 31% of companies surveyed are concerned about the VOLUME OF DATA STORE they need to protect Source: “EU General Data Protection Regulation Survey,” Boldonjames.com. Access at: https://www.boldonjames.com/resources/eu-data-protection-regulation-survey-infographic/. 36% of companies surveyed believe changing processes around DATA PROTECTION and MANAGEMENT is the biggest challenge 4 Copyright © 2018 Accenture. All rights reserved. Accenture’s research into consumer behavior suggests data privacy and protection is not just about compliance and should be at the core of wider business strategy. 8out of 10 surveyed consumers say trust is a key driver of brand loyalty† Consumers surveyed would consider asking their financial services provider to delete personal data, About 2 out of 3 †† 4 out of 10 consumers surveyed, trust in a company increases when breaches are handled swiftly and correctly† of UK consumers surveyed are willing to share their personal information with their bank in return for certain added benefits and more personalized, relevant services 54%†† † A New Slice of PI, with a Side of Digital Trust, Accenture 2017. † † UK Financial Services Customer Survey 2018, Accenture 2018.
  • 5. Copyright © 2018 Accenture. All rights reserved. 5 REGULATORY CONTEXT AND INDUSTRY CHALLENGES GDPR COMPLIANCE IS FAR FROM BEING A SINGLE ONE-OFF REMEDIATION EFFORT AND MOST ORGANIZATIONS MAY NOT BE FULLY COMPLIANT BY 25TH MAY, 2018 2018 ACHIEVE “DEFENSIBLE” COMPLIANCE POSITION BASED ON RISK APPETITE IMPLEMENT GDPR MEASURES TO MITIGATE “RESIDUAL RISKS” STATEGIC GDPR DIFFERENTIATION  Implement data deletion and security measures for medium - low risk areas  Improve data governance and data discovery  Improve third party due- diligence / risk management  Increase customer trust by improving privacy controls and culture  Help reduce cost of data operations  Leverage data as a strategic differentiator  Reduce third-party supplier risk  Implement new GDPR Governance Model  Implement new subject rights and consent framework  Implement data deletion and security measures for high risk areas 2019 MARKET INSIGHTS MAY High Impact: GDPR is a complex game with high impact on Systems Risk-Based Approach: Clients’ GDPR is too big to be totally completed by 2018 – primary focus should be on the highest risk areas with an intent to cover in a second step the remaining ones Different actions according to Maturity Level: The action plan is linked to the maturity level / state of art of the Privacy Framework / existing solutions / projects
  • 6. Users have the right to be forgotten; data should be erased on request Organizations have to notify authorities of data breaches Personal data is portable, and can be transferred on request Organizations handling personal data have to assign a data protection officer A user should be able to easily withdraw, and give informed data collection consent Security / Privacy by design; for solutions and processes related to handling / collecting of personal data, privacy and security should be prioritized Organizationscanbeauditedtoprovetheir compliancewithGDPR Organizations have to follow the data minimization principle; only collect data which is directly relevant and necessary to accomplish a specified purpose OPERATIONAL THEMES TO BECOME GDPR READY All data should be adequately protected and consent secured 6Copyright © 2018 Accenture. All rights reserved.
  • 7. Copyright © 2018 Accenture. All rights reserved. 7 OPPORTUNITIES AND CONSIDERATIONS FOR THE FUTURE GDPR impacts across businesses, thus requires a cross-functional team It is not just a Risk, IT, Security or legal project – business involvement is key 1 Ensure you understand accountability of data controllers This is more than just a name in the frame, it is about where it may be funded from and who has influence to make the change happen across the organization 6 Customer journey led discovery Identify the top 5-10 customer journeys, they may often drive out the biggest risks like data movement across Utility entities and across systems and prioritize remediation accordingly 2 Embed the Data Protection Officer (DPO) in the organization Ensure that the DPO has the right capabilities (skills, team, authority) and is empowered to highlight risks and make changes happen 7 Prioritize on risks and demonstrate change In many ways GDPR might be too big to be totally completed by 2018 – focus on the highest risks first with an intent to cover all areas 3 Alliance and partners are your responsibility You are now accountable for your alliance / partners being Data Processors and these are often obscure e.g. cloud providers 4 Assess existing projects to scale Data privacy should be a part of all data-related projects, not just a one-time dedicated program 5 Different parts of the organization can be different in maturity It’s natural for some areas to be further ahead, use the wins of leading parts of the organization and make sure all areas are coordinated 8 Tools and organizational experience are critical There is no silver bullet to GDPR compliance. There should be no substitute for engaging stakeholders around the enterprise to understand the hidden nuances in getting to a compliant position 9 From burden to opportunity GDPR investment can be leveraged to drive business value and opportunities e.g. establishing simpler data operations and potentially reduce the cost and data noise 10
  • 8. FROM BURDEN TO OPPORTUNITY A defined customer data strategy may help companies to turn regulatory burden and challenges into a competitive advantage. Stricter consent Detailed records on data use New categories of personal data Stricter governance Data privacy by design Accountability for 3rd party sharing Minimization of customer data Right to be forgotten Improve marketing opt-in More efficient data operations More comprehensive profiles Value-based data investments Improved ROI of new initiatives More value from data sharing Potential reduction of cost and data noise Improved marketing spend Enhance consent model /Value exchange Enterprise-wide customer data mapping Treat digital shadow as customer data Put customer data into business ownership Business cases with value / risk of customer data Define 3rd party data sharing strategy Cleanse data lakes from no-value records Stop targeting customers that are not interested From Burden... ...to Opportunity 8Copyright © 2018 Accenture. All rights reserved.
  • 9. Copyright © 2018 Accenture. All rights reserved. 9 PRIVACY ACT – WHAT’S THE BILL GOING TO DO? Personal Info Collected Personal Information Sold Right to Say No The California Consumer Privacy Act of 2018 is going to put safeguards in place to further project consumers privacy. If enacted the bill will govern the way a consumer’s personal information is being received, held and shared with businesses. The bill has severe implications to businesses that handle or share consumer(s) information. The 8 sections outlined below are components of the bill and will cover how Personal Information (PI) should be handled. 2 3 Equal Service and Price Disclosure Requirements Notice Requirements 5 6 4 Clarifying Definitions Exemptions 7 1 8 Biometric data Personal identifiers like real name, alias, account name, etc. Audio, electronic, visual, thermal Inferences to any PI info Any PI related to children of consumer Internet or network activity info Psychometric Info Geolocation data Records of property, products or services provided Professional or employment- related info Examples of Personal Information Accenture analysis based upon publicly available documents.
  • 10. Copyright © 2018 Accenture. All rights reserved. 10 ACCENTURE CONTACT INFORMATION Lisa Bloomberg Principal Director Financial Services Regulatory & Compliance New York Lisa.Bloomberg@Accenture.com Tel: +1 917-452-6247 Chris Beck Senior Manager Financial Services Regulatory & Compliance Chicago Christoper.t.beck@Accenture.com Tel: +1 312-693-6246 Samantha Regan Managing Director Financial Services Regulatory & Compliance Management Lead for North America samantha.regan@accenture.com Tel: +1 404-790-7378 Ben Shorten Senior Manager Financial Services Regulatory & Compliance New York benjamin.j.shorten@accenture.com Tel: +1 (512) 739 4080 Daniel J. Maloney Senior Manager Regulatory & Compliance Charlotte Daniel.Maloney@Accenture.com Tel: +1 908-489-4602
  • 11. Copyright © 2018 Accenture. All rights reserved. 11 GDPR DATA PRIVACY IN THE NEW About Accenture Accenture is a leading global professional services company, providing a broad range of services and solutions in strategy, consulting, digital, technology and operations. Combining unmatched experience and specialized skills across more than 40 industries and all business functions—underpinned by the world’s largest delivery network—Accenture works at the intersection of business and technology to help clients improve their performance and create sustainable value for their stakeholders. With more than 442,000 people serving clients in more than 120 countries, Accenture drives innovation to improve the way the world works and lives. Visit us at www.accenture.com Accenture, its logo, and High Performance Delivered are trademarks of Accenture. Disclaimer This presentation is intended for general informational purposes only and does not take into account the reader’s specific circumstances, and may not reflect the most current developments. Accenture disclaims, to the fullest extent permitted by applicable law, any and all liability for the accuracy and completeness of the information in this presentation and for any acts or omissions made based on such information. Accenture does not provide legal, regulatory, audit, or tax advice. Readers are responsible for obtaining such advice from their own legal counsel or other licensed professionals.