SlideShare a Scribd company logo
1 of 41
9 Steps 2 GDPR Compliance
General Data Protection Regulation (GDPR),
since May 25th, 2018
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
Text, Important Text
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
Terminology
What is personal data?
Any information relating to an identified or identifiable natural
person. Such as name, age, residence, occupation, location, marital
status, natural characteristics, education, job description, interests,
activities, habits, hobbies etc.
The identified or identifiable natural person under the aforementioned
data is called the Data Subject.
Terminology
What is sensitive personal data?
Any information regarding the Data Subject including the racial or
ethnic origin, political opinions, religious beliefs or other beliefs of a
similar nature, physical or mental health or condition, sex life, whether
the DS is a member of a trade union, the commission or alleged
commission by the DS of any offence, any proceedings for any offence
committed or alleged to have been committed by him, the sentence of
any court etc.
Sensitive personal data is protected under stricter regulations.
Ορολογία
DS: Data Subject - the identified or identifiable natural person whose
data we collect.
DC: Data Controller – the person (or business) who determines the
purposes for which, and the way in which, personal data is processed.
DP: Data Processor – anyone who processes personal data on behalf
of the data controller.
DPO: Data Protection Officer – responsible for overseeing data
protection strategy and implementation to ensure compliance with
GDPR requirements.
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
About the Data (2 questions)
1. Do I have the right to own data?
Note: In any case, I have the right to keep personal data when it is
covered by a legal act (recruitment, financial transaction, invoicing,
contracts and family data, employee’s medical counseling, maternity
and pregnancy leave, civil status, etc.). In such cases I am entitled to
and obliged, by law, to keep data on the data subjects for a minimum
period of 5 – 6 years, for most European countries.
About the Data (2 questions)
2. How do I protect the data that I keep?
Contents
Terminology
About the Data
Fines
9 Steps to Compliance
Fines
Fines up to 20 Million Euros or more, but before we start getting that
scared, we may receive...
1. Warnings
2. Reprimands
3. Orders to compliance with the DS’s requests
4. Orders to communicate the data breaches directly to the DS
Fines
Categories:
Tier I: 10 Million Euros or 10% of annual turnover (whichever is higher)
- Breaches of Data Controller and Data Processor obligations.
Tier II: 10 Million Euros or 10% of annual turnover (whichever is higher)
- Breaches of DS's rights.
Fines
Value of the fines to be imposed is not straightforward and the
organization’s steps to compliance and general behavior will be taken
into account when determining the fine.
Available information is unclear full of jargon.
Terminology
About the Data
Fines
9 Steps to Compliance
STEP 1 – Data Gathering
Gather, store and organize all your data in one place.
Key Points
• You have to be able to get anyone’s data asap and aaap (accurately), if
ever asked.
• You have to show that you know exactly what data you have on who
and where, if ever investigated by GDPR.
• You have to gather all existing Personal Data.
STEP 2 – Data Audit
Audit your data and dispose what you don’t need.
Key Points
• Why do you have other people's data?
• Categorize your data to: not useful anymore, useful but harmless,
useful and risky (medical, financial).
• Delete all data you don't need.
STEP 3 – Secure Data
Protect against breaches, hacks, blocks and ransomware,
destruction and deletion of data etc.
Key Points
• Cloud Security
• Active Protection (antivirus, firewall, remote wipe out of data)
• Security for Hard Copies of Data (locked, disaster-proof)
NOT RECOMMENDED due to risk and high costs
• Written Procedures on Safety Measures
STEP 4 – Data Policy
Write a clear fair privacy policy.
Key Points
• Document that clearly describes What Data you collect and How You
Use Them.
• Easy Access to the Data Policy (ideally, a link before every submit
button).
• AVOID Technical Language and or Jargon.
STEP 4 – Data Policy
Answer the following (all of them):
1. What Information do you collect?
2. Who are you?
3. How is information collected?
4. Why do you collect information?
STEP 4 – Data Policy
Answer the following (all of them):
5. How will you use information?
6. Who will you share it with?
7. How are people, whose data you have and process, influenced?
8. Is the intended use likely to cause objections?
STEP 5 – Export Data
Setup a process for exporting all data you have on a person.
Key Points
• Provide the requested information within a month and free of
charge.
STEP 6 – Update & Delete Data
Setup a process for updating and / or deleting data, if ever
asked by the DS.
STEP 6 – Update & Delete Data
DANGER, in case you contact a
person you are supposed to have
no data on anymore!
STEP 7 – Positive Opt In, Action & Evidence
We collect data only when the DS proactively submits it!
Key Points
• AVOID pre-checked boxes.
• Clear and visible "Yes, I agree..." checkbox.
• Double opt-in.
• Sign a paper in-person, in case you collect personal data offline.
• Inform all your database about GDPR and encourage subscribers to
re-subscribe or answer back with a copy-paste consenting email.
STEP 8 – Easy Opt Out
Make it easy for anyone to opt-out.
Key Points
• Newsletter
• SMS
• Call Centers
• Provide clear opt-out directions with no small print
STEP 8 – Easy Opt Out
DANGER, in case you contact
an opted-out person!
STEP 9 – Inform
Make sure everyone in your company knows about GDPR.
Make sure customers and vendors also know about GDPR
and review your contracts with them.
Key Points
• Send informative emails.
• Train everyone.
• Assign responsibilities to a Data Protection Officer (DPO) in case your
organization consists of more than 250 employees.
Let’s not forget…
some interesting points concerning a potential data-ownership change!
Data Ownership
SHOULD I BUY DATA?
Make sure the Provider Company is GDPR compliant and each and
every DS in the dataset has actively opted-in for their data to be stored
by a third party company.
In practice, it is advisable not to buy!
Data Ownership
MAYBE I SELL MY BUSINESS ONE DAY! WHAT ABOUT THE
DATA?
There has to be a clear-cut section in your Data Policy stating that in
case of a buying off, all data will be in possession of the new owner.
When that day comes, you should inform the new owner about your
existing data policies and the fact that he has no right to use them in
any other way.
Are you GDPR Compliant?
Andreas Batsis, Digital Strategy & Cloud Security Solutions

More Related Content

What's hot

CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticher
amy_hatton
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
rtjbond
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 

What's hot (20)

EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)EU GDPR(general data protection regulation)
EU GDPR(general data protection regulation)
 
CHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul TicherCHASE 2014 data protection presentation Paul Ticher
CHASE 2014 data protection presentation Paul Ticher
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
Data Protection Audit Checklist
Data Protection Audit ChecklistData Protection Audit Checklist
Data Protection Audit Checklist
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 

Similar to 9 Practical Steps 2 GDPR Compliance

Similar to 9 Practical Steps 2 GDPR Compliance (20)

What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
GDPR - Sink or Swim
GDPR - Sink or SwimGDPR - Sink or Swim
GDPR - Sink or Swim
 
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist  AVG / GDPR - Algemene Verordering GegevensbeschermingMagento checklist  AVG / GDPR - Algemene Verordering Gegevensbescherming
Magento checklist AVG / GDPR - Algemene Verordering Gegevensbescherming
 
The Evolution of Data Privacy: 3 Things You Need To Consider
The Evolution of Data Privacy:  3 Things You Need To ConsiderThe Evolution of Data Privacy:  3 Things You Need To Consider
The Evolution of Data Privacy: 3 Things You Need To Consider
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
GDPR Demystified
GDPR Demystified GDPR Demystified
GDPR Demystified
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...Protection des données et de la vie privée : nouvelles obligations pour les e...
Protection des données et de la vie privée : nouvelles obligations pour les e...
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
 
Taking the Fear Out of GDPR
Taking the Fear Out of GDPRTaking the Fear Out of GDPR
Taking the Fear Out of GDPR
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
GDPR Pop Up | Human Capital Department - HR Forum - 26 April 2018
 
GDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptxGDPR and Cyber Security LW.pptx
GDPR and Cyber Security LW.pptx
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 

More from Andreas Batsis

More from Andreas Batsis (13)

Weatherman 1-hour Speed Course for Web [2023]
Weatherman 1-hour Speed Course for Web [2023]Weatherman 1-hour Speed Course for Web [2023]
Weatherman 1-hour Speed Course for Web [2023]
 
Linked Business - Empowering organizations to achieve evidence-based calculat...
Linked Business - Empowering organizations to achieve evidence-based calculat...Linked Business - Empowering organizations to achieve evidence-based calculat...
Linked Business - Empowering organizations to achieve evidence-based calculat...
 
Linked Business: All-in-one Business Leads
Linked Business: All-in-one Business LeadsLinked Business: All-in-one Business Leads
Linked Business: All-in-one Business Leads
 
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
Linked Business: Πωλήσεις και Ασφαλής Ανάπτυξη των Επιχειρήσεων με τη χρήση τ...
 
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYCThe AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
The AI Banking Sector: Risks & Opportunities with the use of Systemic KYC
 
Linked Business Platform GR - v15
Linked Business Platform GR - v15Linked Business Platform GR - v15
Linked Business Platform GR - v15
 
Crisis-Proof: Strategy for Digital and non-Digital Businesses
Crisis-Proof: Strategy for Digital and non-Digital BusinessesCrisis-Proof: Strategy for Digital and non-Digital Businesses
Crisis-Proof: Strategy for Digital and non-Digital Businesses
 
Linked Business Platform EN - v11
Linked Business Platform EN - v11Linked Business Platform EN - v11
Linked Business Platform EN - v11
 
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
Viable Digital Strategy: Have you forgotten what digital is all about? (v4)
 
Batcic @ Delta, Digital Era (v.11)
Batcic @ Delta, Digital Era (v.11)Batcic @ Delta, Digital Era (v.11)
Batcic @ Delta, Digital Era (v.11)
 
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
Digital 4 Designers - Εφαρμογές των Αρχών του Permission Marketing για τους Γ...
 
iWeatherman
iWeathermaniWeatherman
iWeatherman
 
Εκπαιδευτικός Άτλαντας Νεφών
Εκπαιδευτικός Άτλαντας ΝεφώνΕκπαιδευτικός Άτλαντας Νεφών
Εκπαιδευτικός Άτλαντας Νεφών
 

Recently uploaded

Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get CytotecAbortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Riyadh +966572737505 get cytotec
 
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
vexqp
 
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
nirzagarg
 
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
vexqp
 
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
q6pzkpark
 
一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样
一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样
一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样
wsppdmt
 
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
vexqp
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
gajnagarg
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
wsppdmt
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
ahmedjiabur940
 
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
Health
 
怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制
怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制
怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制
vexqp
 

Recently uploaded (20)

Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get CytotecAbortion pills in Doha Qatar (+966572737505 ! Get Cytotec
Abortion pills in Doha Qatar (+966572737505 ! Get Cytotec
 
Dubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls DubaiDubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls Dubai
 
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
怎样办理伦敦大学毕业证(UoL毕业证书)成绩单学校原版复制
 
Switzerland Constitution 2002.pdf.........
Switzerland Constitution 2002.pdf.........Switzerland Constitution 2002.pdf.........
Switzerland Constitution 2002.pdf.........
 
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
Top profile Call Girls In Tumkur [ 7014168258 ] Call Me For Genuine Models We...
 
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
怎样办理圣地亚哥州立大学毕业证(SDSU毕业证书)成绩单学校原版复制
 
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
一比一原版(曼大毕业证书)曼尼托巴大学毕业证成绩单留信学历认证一手价格
 
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book nowVadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
 
一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样
一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样
一比一原版(UCD毕业证书)加州大学戴维斯分校毕业证成绩单原件一模一样
 
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
怎样办理旧金山城市学院毕业证(CCSF毕业证书)成绩单学校原版复制
 
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24  Building Real-Time Pipelines With FLaNKDATA SUMMIT 24  Building Real-Time Pipelines With FLaNK
DATA SUMMIT 24 Building Real-Time Pipelines With FLaNK
 
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With OrangePredicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
Predicting HDB Resale Prices - Conducting Linear Regression Analysis With Orange
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
 
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi ArabiaIn Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
In Riyadh ((+919101817206)) Cytotec kit @ Abortion Pills Saudi Arabia
 
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
Digital Advertising Lecture for Advanced Digital & Social Media Strategy at U...
 
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
+97470301568>>weed for sale in qatar ,weed for sale in dubai,weed for sale in...
 
怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制
怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制
怎样办理圣路易斯大学毕业证(SLU毕业证书)成绩单学校原版复制
 
Ranking and Scoring Exercises for Research
Ranking and Scoring Exercises for ResearchRanking and Scoring Exercises for Research
Ranking and Scoring Exercises for Research
 
Aspirational Block Program Block Syaldey District - Almora
Aspirational Block Program Block Syaldey District - AlmoraAspirational Block Program Block Syaldey District - Almora
Aspirational Block Program Block Syaldey District - Almora
 

9 Practical Steps 2 GDPR Compliance

  • 1. 9 Steps 2 GDPR Compliance General Data Protection Regulation (GDPR), since May 25th, 2018
  • 2. Contents Terminology About the Data Fines 9 Steps to Compliance Text, Important Text
  • 4. Terminology What is personal data? Any information relating to an identified or identifiable natural person. Such as name, age, residence, occupation, location, marital status, natural characteristics, education, job description, interests, activities, habits, hobbies etc. The identified or identifiable natural person under the aforementioned data is called the Data Subject.
  • 5. Terminology What is sensitive personal data? Any information regarding the Data Subject including the racial or ethnic origin, political opinions, religious beliefs or other beliefs of a similar nature, physical or mental health or condition, sex life, whether the DS is a member of a trade union, the commission or alleged commission by the DS of any offence, any proceedings for any offence committed or alleged to have been committed by him, the sentence of any court etc. Sensitive personal data is protected under stricter regulations.
  • 6. Ορολογία DS: Data Subject - the identified or identifiable natural person whose data we collect. DC: Data Controller – the person (or business) who determines the purposes for which, and the way in which, personal data is processed. DP: Data Processor – anyone who processes personal data on behalf of the data controller. DPO: Data Protection Officer – responsible for overseeing data protection strategy and implementation to ensure compliance with GDPR requirements.
  • 8. About the Data (2 questions) 1. Do I have the right to own data? Note: In any case, I have the right to keep personal data when it is covered by a legal act (recruitment, financial transaction, invoicing, contracts and family data, employee’s medical counseling, maternity and pregnancy leave, civil status, etc.). In such cases I am entitled to and obliged, by law, to keep data on the data subjects for a minimum period of 5 – 6 years, for most European countries.
  • 9. About the Data (2 questions) 2. How do I protect the data that I keep?
  • 11. Fines Fines up to 20 Million Euros or more, but before we start getting that scared, we may receive... 1. Warnings 2. Reprimands 3. Orders to compliance with the DS’s requests 4. Orders to communicate the data breaches directly to the DS
  • 12. Fines Categories: Tier I: 10 Million Euros or 10% of annual turnover (whichever is higher) - Breaches of Data Controller and Data Processor obligations. Tier II: 10 Million Euros or 10% of annual turnover (whichever is higher) - Breaches of DS's rights.
  • 13. Fines Value of the fines to be imposed is not straightforward and the organization’s steps to compliance and general behavior will be taken into account when determining the fine. Available information is unclear full of jargon.
  • 14. Terminology About the Data Fines 9 Steps to Compliance
  • 15.
  • 16. STEP 1 – Data Gathering Gather, store and organize all your data in one place. Key Points • You have to be able to get anyone’s data asap and aaap (accurately), if ever asked. • You have to show that you know exactly what data you have on who and where, if ever investigated by GDPR. • You have to gather all existing Personal Data.
  • 17.
  • 18. STEP 2 – Data Audit Audit your data and dispose what you don’t need. Key Points • Why do you have other people's data? • Categorize your data to: not useful anymore, useful but harmless, useful and risky (medical, financial). • Delete all data you don't need.
  • 19.
  • 20. STEP 3 – Secure Data Protect against breaches, hacks, blocks and ransomware, destruction and deletion of data etc. Key Points • Cloud Security • Active Protection (antivirus, firewall, remote wipe out of data) • Security for Hard Copies of Data (locked, disaster-proof) NOT RECOMMENDED due to risk and high costs • Written Procedures on Safety Measures
  • 21.
  • 22. STEP 4 – Data Policy Write a clear fair privacy policy. Key Points • Document that clearly describes What Data you collect and How You Use Them. • Easy Access to the Data Policy (ideally, a link before every submit button). • AVOID Technical Language and or Jargon.
  • 23. STEP 4 – Data Policy Answer the following (all of them): 1. What Information do you collect? 2. Who are you? 3. How is information collected? 4. Why do you collect information?
  • 24. STEP 4 – Data Policy Answer the following (all of them): 5. How will you use information? 6. Who will you share it with? 7. How are people, whose data you have and process, influenced? 8. Is the intended use likely to cause objections?
  • 25.
  • 26. STEP 5 – Export Data Setup a process for exporting all data you have on a person. Key Points • Provide the requested information within a month and free of charge.
  • 27.
  • 28. STEP 6 – Update & Delete Data Setup a process for updating and / or deleting data, if ever asked by the DS.
  • 29. STEP 6 – Update & Delete Data DANGER, in case you contact a person you are supposed to have no data on anymore!
  • 30.
  • 31. STEP 7 – Positive Opt In, Action & Evidence We collect data only when the DS proactively submits it! Key Points • AVOID pre-checked boxes. • Clear and visible "Yes, I agree..." checkbox. • Double opt-in. • Sign a paper in-person, in case you collect personal data offline. • Inform all your database about GDPR and encourage subscribers to re-subscribe or answer back with a copy-paste consenting email.
  • 32.
  • 33. STEP 8 – Easy Opt Out Make it easy for anyone to opt-out. Key Points • Newsletter • SMS • Call Centers • Provide clear opt-out directions with no small print
  • 34. STEP 8 – Easy Opt Out DANGER, in case you contact an opted-out person!
  • 35.
  • 36. STEP 9 – Inform Make sure everyone in your company knows about GDPR. Make sure customers and vendors also know about GDPR and review your contracts with them. Key Points • Send informative emails. • Train everyone. • Assign responsibilities to a Data Protection Officer (DPO) in case your organization consists of more than 250 employees.
  • 37. Let’s not forget… some interesting points concerning a potential data-ownership change!
  • 38.
  • 39. Data Ownership SHOULD I BUY DATA? Make sure the Provider Company is GDPR compliant and each and every DS in the dataset has actively opted-in for their data to be stored by a third party company. In practice, it is advisable not to buy!
  • 40. Data Ownership MAYBE I SELL MY BUSINESS ONE DAY! WHAT ABOUT THE DATA? There has to be a clear-cut section in your Data Policy stating that in case of a buying off, all data will be in possession of the new owner. When that day comes, you should inform the new owner about your existing data policies and the fact that he has no right to use them in any other way.
  • 41. Are you GDPR Compliant? Andreas Batsis, Digital Strategy & Cloud Security Solutions