SlideShare ist ein Scribd-Unternehmen logo
1 von 15
GENERAL DATA PROTECTION REGULATION
(GDPR)
A guide to security and data protection in life sciences
Preparing for 2018
 To create a UNIFIED DATA PROTECTION LAW for all 28 European Countries.
 To ENHANCE THE LEVEL OF DATA PROTECTION for EU data subjects
 To MODERNIZE THE LAW in line with existing and emerging technologies
GDPR will fundamentally change the way
companies must manage their data
PRIMARY OBJECTIVES OF THE GDPR
GDPR came into force in May 2016 and will be applicable as of
25 May 2018
• It also has international reach – applying to any organization
that processes data of EU data subjects.
• Fines for non-compliance will increase substantially up to a
maximum fine of € 20 million or 4% of global annual turnover
per incident, whichever is higher
KEY ASPECTS OF THE REGULATION
MEDICAL DEPARTMENT
 Nursing department
 Medical laboratories
 Biomedical technology
 Pharmacy
ADMINISTRATIVE SERVICES
 The board
 Human Recourses,
 Legal , Compliance
 Procurement
 Medical record maintenance department
 IT, marketing and planning ,
 education and Training ,
 Billing and Collection ,
 material management,
 Hospital security
HEALTH CARE PROVIDER’ S ORGANIZATIONAL STRUCTURE
Lawfulness, fairness and transparency
 Personal data must be processed lawfully, fairly, and in a transparent manner
 Personal data must be collected for specified, explicit and legitimate purposes
and not further processed in a way incompatible with those purposes.
 Data minimization Personal data must be adequate, relevant and limited to
those which are necessary
 Accuracy Personal data must be accurate and, where necessary, kept up to
date;
 Storage limitation they should be kept for no longer than is necessary
 Integrity and confidentiality appropriate security of the personal data,
including protection against unauthorised or unlawful processing and against
accidental loss, destruction or damage.
KEY PRINCIPLES
•Erasure
•Rectification
•Data Portability and data sharing
stating that the data subject has the right to receive their data in an appropriate
format without hindrance and for data to be transferred between data controllers
where technically feasible
•Restricted Automated decisions and profiling
• Objection to direct marketing
• Claim of compensation from the data controller or processor for damage suffered
■ member states should enact local laws providing criminal sanctions for a
breach of the GDPR.
■ Claims or complaints may be made by not-for-profit bodies, organisations or
associations.
■ on behalf of a group of data subjects.
NEW RIGHTS FOR THE INDIVIDUAL
The appointment of a data protection officer (DPO)
The obligation to carry out privacy risk impact assessments (DPIA)
New data breach notification requirements
Requirement to apply Privacy by design and by Default,
Appropriate Documentation
Monitoring and verifying compliance regular audit
Consent necessary to process children’s data
Changes to the rules for obtaining valid consent
Heavy Fines for controller and PROCESSOR
ENHANCED OBLIGATIONS
Data protection: hidden risks, clear opportunities
Or the opposite :
Data protection: clear risks, hidden opportunities
INVOLVE THE BOARD
hBOARD
REGY 05
.
COMPLIANCE
BOARD
HRDPO
SUBJECTS
LEGAL FINANCE
PROCUREMEN
T
SUPPORT TEAM- THE GATE
KEEPERS
IT/CIO CRO
DIRECT LINES
OF
COMMUNICATION
AUTHORITIES
4
create DATA FLOW MAPPING
conduct RISK ANALYSIS and DPIA
Run a GDPR compliance GAP ANALYSIS
Implement SECURITY MEASURES
PROJECT GDPR COMPLIANCE 1/4
 DISASTER RECOVERY PLAN
 PRIVACY AND DATA PROTECTION POLICIES
 DATA SUBJECT ACCESS REQUEST (DSAR) PROTOCOLS
 DATA BREACH PROTOCOLS
 SECURITY POLICIES
 DATA RETENTION POLICIES
 DATA SUBJECT NOTIFICATIONS
 INCIDENT RESPONSE PLANS
 DATA TRANSFER AND DATA SHARING AGREEMENTS
 DATA PROCESSING AGREEMENTS
DRAFT POLICIES, PLANS AND PROCEDURES
PROJECT GDPR COMPLIANCE 2/4
TRAINING PROCESS AND AWARENESS PROGRAMS
KEY VENDOR CONTRACTS / THIRD-PARTY RISK
CONSENT OF DATA SUBJECTS
NOTIFICATIONS TO DATA SUBJECTS &
DATA SUBJECT’S RIGHT TO ACCESS, MODIFY, TRANSFER
DATA
PROJECT GDPR COMPLIANCE 3/4
10
DATA BREACH NOTIFICATION
■ describe the nature of the breach;
■ state the number of the data subjects affected by the breach;
■ describe the likely consequences of the breach;
■ describe the measures taken or proposed to be taken by the controller to remedy
the breach.
■ There is a tight deadline of 72 hours
INTERNAL BREACH NOTIFICATION PROCEDURES
 identification systems and incident response plans
 Internal breach register:
 Insurance policies
PROJECT GDPR COMPLIANCE 4/4
MONITORING & AUDITING- IMPROVEMENTS
GDPR IS NOT A DEADLINE OR A
DESTINATION,
IT IS A JOURNEY
Anthe Papageorgiou
Compliance Officer , Data Protection Officer (DPO)
Ε : anthipapage@yahoo.gr
LinkedIN : Anthe Papageorgiou
Tweeter : @AnthePapageorg1

Weitere ähnliche Inhalte

Was ist angesagt?

Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationGhostery, Inc.
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
Introduction to gdpr
Introduction to gdprIntroduction to gdpr
Introduction to gdpr3GDR
 

Was ist angesagt? (20)

General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
Introduction to gdpr
Introduction to gdprIntroduction to gdpr
Introduction to gdpr
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 

Ähnlich wie GDPR The New Data Protection Law coming into effect May 2018. What does it mean for hospitals?

My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRzayadeen2003
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessSirius
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the Newaccenture
 
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to SuccessAddressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to SuccessSirius
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare IndustryEMMAIntl
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...ARMA International
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
Data Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxData Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxAdarsh748147
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterBigDataExpo
 
MRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational MeasuresMRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational MeasuresMRS
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 

Ähnlich wie GDPR The New Data Protection Law coming into effect May 2018. What does it mean for hospitals? (20)

My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
GDPR: Data Privacy in the New
GDPR: Data Privacy in the NewGDPR: Data Privacy in the New
GDPR: Data Privacy in the New
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
GDPR
GDPRGDPR
GDPR
 
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to SuccessAddressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
GDPR infographic
GDPR infographicGDPR infographic
GDPR infographic
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
Data Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptxData Privacy and Security in UAE.pptx
Data Privacy and Security in UAE.pptx
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
GDPR How to get started?
GDPR  How to get started?GDPR  How to get started?
GDPR How to get started?
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
De groote de man Ingrid de Poorter
De groote de man Ingrid de PoorterDe groote de man Ingrid de Poorter
De groote de man Ingrid de Poorter
 
MRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational MeasuresMRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational Measures
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 

Mehr von eHealth Forum

4th Athens Digital Health meetup
4th Athens Digital Health meetup4th Athens Digital Health meetup
4th Athens Digital Health meetupeHealth Forum
 
Big data for precision medicine: challenges and opportunities
Big data for precision medicine: challenges and opportunitiesBig data for precision medicine: challenges and opportunities
Big data for precision medicine: challenges and opportunitieseHealth Forum
 
The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...
The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...
The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...eHealth Forum
 
Digitalized Public Hospital under the Stethoscope: 5Ws and an H
Digitalized Public Hospital under the Stethoscope: 5Ws and an HDigitalized Public Hospital under the Stethoscope: 5Ws and an H
Digitalized Public Hospital under the Stethoscope: 5Ws and an HeHealth Forum
 
Report: Greek Delegation at eHealth Week 2017, Malta
Report: Greek Delegation at eHealth Week 2017, MaltaReport: Greek Delegation at eHealth Week 2017, Malta
Report: Greek Delegation at eHealth Week 2017, MaltaeHealth Forum
 
Advancing eHealth in Greece - eHealth Week'17 Outcomes
Advancing eHealth in Greece - eHealth Week'17 OutcomesAdvancing eHealth in Greece - eHealth Week'17 Outcomes
Advancing eHealth in Greece - eHealth Week'17 OutcomeseHealth Forum
 
Knowing me, knowing you, knowing your disease
Knowing me, knowing you, knowing your diseaseKnowing me, knowing you, knowing your disease
Knowing me, knowing you, knowing your diseaseeHealth Forum
 
Unraveling the opportunities & challenges of the Greek eHealth Ecosystem
Unraveling the  opportunities & challenges of the Greek eHealth EcosystemUnraveling the  opportunities & challenges of the Greek eHealth Ecosystem
Unraveling the opportunities & challenges of the Greek eHealth EcosystemeHealth Forum
 
Advancing eHealth in Greece
Advancing eHealth in GreeceAdvancing eHealth in Greece
Advancing eHealth in GreeceeHealth Forum
 
Blockchain Technology for Patients Medical Records
Blockchain Technology for Patients Medical RecordsBlockchain Technology for Patients Medical Records
Blockchain Technology for Patients Medical RecordseHealth Forum
 
The Greek ePrescription System
The Greek ePrescription SystemThe Greek ePrescription System
The Greek ePrescription SystemeHealth Forum
 
The Impact of Digital Health on Our Everyday Lives
The Impact of Digital Health on Our Everyday Lives The Impact of Digital Health on Our Everyday Lives
The Impact of Digital Health on Our Everyday Lives eHealth Forum
 
Planning the eHealth Forum of tomorrow
Planning the eHealth Forum of tomorrow Planning the eHealth Forum of tomorrow
Planning the eHealth Forum of tomorrow eHealth Forum
 
Does Greece have an eHealth strategy plan?
Does Greece have an eHealth strategy plan? Does Greece have an eHealth strategy plan?
Does Greece have an eHealth strategy plan? eHealth Forum
 

Mehr von eHealth Forum (14)

4th Athens Digital Health meetup
4th Athens Digital Health meetup4th Athens Digital Health meetup
4th Athens Digital Health meetup
 
Big data for precision medicine: challenges and opportunities
Big data for precision medicine: challenges and opportunitiesBig data for precision medicine: challenges and opportunities
Big data for precision medicine: challenges and opportunities
 
The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...
The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...
The P4 Initiative: Personalized - Predictive - Preventive - Participatory Med...
 
Digitalized Public Hospital under the Stethoscope: 5Ws and an H
Digitalized Public Hospital under the Stethoscope: 5Ws and an HDigitalized Public Hospital under the Stethoscope: 5Ws and an H
Digitalized Public Hospital under the Stethoscope: 5Ws and an H
 
Report: Greek Delegation at eHealth Week 2017, Malta
Report: Greek Delegation at eHealth Week 2017, MaltaReport: Greek Delegation at eHealth Week 2017, Malta
Report: Greek Delegation at eHealth Week 2017, Malta
 
Advancing eHealth in Greece - eHealth Week'17 Outcomes
Advancing eHealth in Greece - eHealth Week'17 OutcomesAdvancing eHealth in Greece - eHealth Week'17 Outcomes
Advancing eHealth in Greece - eHealth Week'17 Outcomes
 
Knowing me, knowing you, knowing your disease
Knowing me, knowing you, knowing your diseaseKnowing me, knowing you, knowing your disease
Knowing me, knowing you, knowing your disease
 
Unraveling the opportunities & challenges of the Greek eHealth Ecosystem
Unraveling the  opportunities & challenges of the Greek eHealth EcosystemUnraveling the  opportunities & challenges of the Greek eHealth Ecosystem
Unraveling the opportunities & challenges of the Greek eHealth Ecosystem
 
Advancing eHealth in Greece
Advancing eHealth in GreeceAdvancing eHealth in Greece
Advancing eHealth in Greece
 
Blockchain Technology for Patients Medical Records
Blockchain Technology for Patients Medical RecordsBlockchain Technology for Patients Medical Records
Blockchain Technology for Patients Medical Records
 
The Greek ePrescription System
The Greek ePrescription SystemThe Greek ePrescription System
The Greek ePrescription System
 
The Impact of Digital Health on Our Everyday Lives
The Impact of Digital Health on Our Everyday Lives The Impact of Digital Health on Our Everyday Lives
The Impact of Digital Health on Our Everyday Lives
 
Planning the eHealth Forum of tomorrow
Planning the eHealth Forum of tomorrow Planning the eHealth Forum of tomorrow
Planning the eHealth Forum of tomorrow
 
Does Greece have an eHealth strategy plan?
Does Greece have an eHealth strategy plan? Does Greece have an eHealth strategy plan?
Does Greece have an eHealth strategy plan?
 

Kürzlich hochgeladen

Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeCall Girls Delhi
 
O898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
O898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In AhmedabadO898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
O898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In AhmedabadGenuine Call Girls
 
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...chandars293
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Varanasi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Varanasi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Agra Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Agra Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Agra Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Agra Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...hotbabesbook
 
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort ServicePremium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Servicevidya singh
 
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...parulsinha
 
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...parulsinha
 
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Top Rated Bangalore Call Girls Richmond Circle ⟟ 9332606886 ⟟ Call Me For Ge...
Top Rated Bangalore Call Girls Richmond Circle ⟟  9332606886 ⟟ Call Me For Ge...Top Rated Bangalore Call Girls Richmond Circle ⟟  9332606886 ⟟ Call Me For Ge...
Top Rated Bangalore Call Girls Richmond Circle ⟟ 9332606886 ⟟ Call Me For Ge...narwatsonia7
 
Call Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Guntur Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Guntur  Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Guntur  Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Guntur Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...perfect solution
 
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 

Kürzlich hochgeladen (20)

Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
 
O898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
O898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In AhmedabadO898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
O898O367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
 
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 9332606886 𖠋 Will You Mis...
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
 
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls Varanasi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Varanasi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls Agra Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Agra Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Agra Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Agra Just Call 8250077686 Top Class Call Girl Service Available
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
 
Call Girls in Gagan Vihar (delhi) call me [🔝 9953056974 🔝] escort service 24X7
Call Girls in Gagan Vihar (delhi) call me [🔝  9953056974 🔝] escort service 24X7Call Girls in Gagan Vihar (delhi) call me [🔝  9953056974 🔝] escort service 24X7
Call Girls in Gagan Vihar (delhi) call me [🔝 9953056974 🔝] escort service 24X7
 
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort ServicePremium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
 
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
 
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
 
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
 
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
 
Top Rated Bangalore Call Girls Richmond Circle ⟟ 9332606886 ⟟ Call Me For Ge...
Top Rated Bangalore Call Girls Richmond Circle ⟟  9332606886 ⟟ Call Me For Ge...Top Rated Bangalore Call Girls Richmond Circle ⟟  9332606886 ⟟ Call Me For Ge...
Top Rated Bangalore Call Girls Richmond Circle ⟟ 9332606886 ⟟ Call Me For Ge...
 
Call Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls Guntur Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Guntur  Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Guntur  Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Guntur Just Call 8250077686 Top Class Call Girl Service Available
 
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
 
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Ooty Just Call 8250077686 Top Class Call Girl Service Available
 

GDPR The New Data Protection Law coming into effect May 2018. What does it mean for hospitals?

  • 1. GENERAL DATA PROTECTION REGULATION (GDPR) A guide to security and data protection in life sciences Preparing for 2018
  • 2.  To create a UNIFIED DATA PROTECTION LAW for all 28 European Countries.  To ENHANCE THE LEVEL OF DATA PROTECTION for EU data subjects  To MODERNIZE THE LAW in line with existing and emerging technologies GDPR will fundamentally change the way companies must manage their data PRIMARY OBJECTIVES OF THE GDPR
  • 3. GDPR came into force in May 2016 and will be applicable as of 25 May 2018 • It also has international reach – applying to any organization that processes data of EU data subjects. • Fines for non-compliance will increase substantially up to a maximum fine of € 20 million or 4% of global annual turnover per incident, whichever is higher KEY ASPECTS OF THE REGULATION
  • 4. MEDICAL DEPARTMENT  Nursing department  Medical laboratories  Biomedical technology  Pharmacy ADMINISTRATIVE SERVICES  The board  Human Recourses,  Legal , Compliance  Procurement  Medical record maintenance department  IT, marketing and planning ,  education and Training ,  Billing and Collection ,  material management,  Hospital security HEALTH CARE PROVIDER’ S ORGANIZATIONAL STRUCTURE
  • 5. Lawfulness, fairness and transparency  Personal data must be processed lawfully, fairly, and in a transparent manner  Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes.  Data minimization Personal data must be adequate, relevant and limited to those which are necessary  Accuracy Personal data must be accurate and, where necessary, kept up to date;  Storage limitation they should be kept for no longer than is necessary  Integrity and confidentiality appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. KEY PRINCIPLES
  • 6. •Erasure •Rectification •Data Portability and data sharing stating that the data subject has the right to receive their data in an appropriate format without hindrance and for data to be transferred between data controllers where technically feasible •Restricted Automated decisions and profiling • Objection to direct marketing • Claim of compensation from the data controller or processor for damage suffered ■ member states should enact local laws providing criminal sanctions for a breach of the GDPR. ■ Claims or complaints may be made by not-for-profit bodies, organisations or associations. ■ on behalf of a group of data subjects. NEW RIGHTS FOR THE INDIVIDUAL
  • 7. The appointment of a data protection officer (DPO) The obligation to carry out privacy risk impact assessments (DPIA) New data breach notification requirements Requirement to apply Privacy by design and by Default, Appropriate Documentation Monitoring and verifying compliance regular audit Consent necessary to process children’s data Changes to the rules for obtaining valid consent Heavy Fines for controller and PROCESSOR ENHANCED OBLIGATIONS
  • 8. Data protection: hidden risks, clear opportunities Or the opposite : Data protection: clear risks, hidden opportunities INVOLVE THE BOARD
  • 9. hBOARD REGY 05 . COMPLIANCE BOARD HRDPO SUBJECTS LEGAL FINANCE PROCUREMEN T SUPPORT TEAM- THE GATE KEEPERS IT/CIO CRO DIRECT LINES OF COMMUNICATION AUTHORITIES
  • 10. 4 create DATA FLOW MAPPING conduct RISK ANALYSIS and DPIA Run a GDPR compliance GAP ANALYSIS Implement SECURITY MEASURES PROJECT GDPR COMPLIANCE 1/4
  • 11.  DISASTER RECOVERY PLAN  PRIVACY AND DATA PROTECTION POLICIES  DATA SUBJECT ACCESS REQUEST (DSAR) PROTOCOLS  DATA BREACH PROTOCOLS  SECURITY POLICIES  DATA RETENTION POLICIES  DATA SUBJECT NOTIFICATIONS  INCIDENT RESPONSE PLANS  DATA TRANSFER AND DATA SHARING AGREEMENTS  DATA PROCESSING AGREEMENTS DRAFT POLICIES, PLANS AND PROCEDURES PROJECT GDPR COMPLIANCE 2/4
  • 12. TRAINING PROCESS AND AWARENESS PROGRAMS KEY VENDOR CONTRACTS / THIRD-PARTY RISK CONSENT OF DATA SUBJECTS NOTIFICATIONS TO DATA SUBJECTS & DATA SUBJECT’S RIGHT TO ACCESS, MODIFY, TRANSFER DATA PROJECT GDPR COMPLIANCE 3/4
  • 13. 10 DATA BREACH NOTIFICATION ■ describe the nature of the breach; ■ state the number of the data subjects affected by the breach; ■ describe the likely consequences of the breach; ■ describe the measures taken or proposed to be taken by the controller to remedy the breach. ■ There is a tight deadline of 72 hours INTERNAL BREACH NOTIFICATION PROCEDURES  identification systems and incident response plans  Internal breach register:  Insurance policies PROJECT GDPR COMPLIANCE 4/4 MONITORING & AUDITING- IMPROVEMENTS
  • 14. GDPR IS NOT A DEADLINE OR A DESTINATION, IT IS A JOURNEY
  • 15. Anthe Papageorgiou Compliance Officer , Data Protection Officer (DPO) Ε : anthipapage@yahoo.gr LinkedIN : Anthe Papageorgiou Tweeter : @AnthePapageorg1

Hinweis der Redaktion

  1. PRIVACY PRINCIPLES FOR THE HEALTHCARE PROVIDER  The changes to data protection rules are not revolutionary – the key principles, remain in place but with many new requirements Some Remain Consistent with the Directive 95/46/CE Lawfulness, fairness and transparency Personal data must be processed lawfully, fairly, and in a transparent manner Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Data minimization Personal data must be adequate, relevant and limited to those which are necessary Accuracy Personal data must be accurate and, where necessary, kept up to date; Storage limitation they should be kept for no longer than is necessary Integrity and confidentiality appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
  2. new rights for the individual Erasure •Rectification •Data Portability and data sharing/ stating that the data subject has the right to receive their data in an appropriate format without hindrance and for data to be transferred between data controllers where technically feasible •Restricted Automated decisions and profiling • Objection to direct marketing • Claim of compensation from the data controller or processor for damage suffered ■ member states should enact local laws providing criminal sanctions for a breach of the GDPR. ■ Claims or complaints may be made by not-for-profit bodies, organisations or associations. ■ on behalf of a group of data subjects
  3. The obligation to keep an internal register ,a record of all data processing activities. available for inspection to the supervisory authority upon request. The appointment of a data protection officer (DPO) The obligation to carry out privacy risk impact assessments DPIA New data breach notification requirements Requirement to apply Privacy by design and by Default, Appropriate Documentation maintaining a clear written record of all data operations Monitoring and verifying compliance regular audit Consent necessary to process children’s data Changes to the rules for obtaining valid consent Heavy Fines for controller and PROCESSOR Under the GDPR, the maximum amount of financial sanctions is harmonized and increased up to 4% of the total worldwide annual turnover or 20 million euros, whichever is the greater
  4. AS A FIRST STEP΄¨ ADVISE MEMBERS OF THE BOARD TO ASSIGN RESPONSIBILITY AND BUDGET FOR DATA PROTECTION COMPLIANCE WITHIN YOUR HOSPITAL You should ask them Are YOU investing appropriately in protecting our network, computing devices, Internet-connected devices and data relevant to their value and criticality to the operation of our hospital?   Do YOU consider cyber security a part of our overall strategic and operational business decisions? The five principles of the Boards responsibility by The National Association of Corporate Directors concerning cyber security : PRINCIPLE 1: Directors need to understand and approach cyber security as an enterprisewide risk-management issue, not just an IT issue. PRINCIPLE 2: Directors should understand the legal implications of cyber risks as they relate to their company’s specific circumstances. PRINCIPLE 3: Boards should have adequate access to cyber security expertise, and discussions about cyber-risk management should be given regular and adequate time on the board meeting agenda. PRINCIPLE 4: Directors should set the expectation that management will establish an enterprise-wide, cyber-risk management framework with adequate staffing and budget. PRINCIPLE 5: Board discussion of cyber risk management should include identification of which risks to avoid, accept, mitigate, or transfer through insurance, as well as specific plans associated with each approach. The board should Develop an implement governance framework, The Dpo should proposE, design and implement solutions that protect access and align to business growth Objectives Then you should help them build a culture of privacy through awareness programs
  5.  As you can see there s a direct line of communication with the board, subjects and authorities. The DPO should involve key persons and make a supporting Team . Those usually are ΙΤ-cio ATTENDS processes pertaining to data security, availability and confidentiality and ensure that they are well documented, DR systems. a breach of data security,  -CROs- The head of risk perhaps the most important person within an organisation in ensuring that GDPR compliance is maintained. s will be responsible for setting compliance frameworks and audits, interpreting the GDPR and assessing risk,  HR . Because as a DPO you have to protect the staff as well, and treat employees as personal data subjects What kind of personal data and sensitive p data do u keep? Do you obtain consent and is it valid under GDPR? how long do you keep them?  Legal AND COMPLIANCE . How they should deal with a request, or multiple concurrent requests for provision of p.d ? Is your answer within GDPR deadline? Is there a documented process? Review of all contracts  Procurement Are there sub-contractors processing pd on your behalf? Do they take all safety measures to protect pd? Do they meet the GDPR requirements?  
  6. CREATE DATA MAPPING you need to discover and classify P.D What & where is it? Understand and document where Personal Data is stored and processed, including with/by 3rd parties Why it matters: • Hospitals like any other organization need to understand what data they hold and process to assess risk and design adequate controls • are necessary to support Data Portability,Right of Access, CONDUCT RISK ANALYSIS AND DATA PROTECTION IMPACT ASSESSMENTS Identify significant risks and areas which require immediate action to help you better manage risk The Data Protection Impact Assessments include assessing risks, ‘including safeguards, security measures and mechanisms to ensure the protection of personal data and demonstrate compliance with this regulation  RUN A GDPR COMPLIANCE GAP ANALYSIS - ACCESS YOURSELF to identify areas of most material noncompliance and to priorities mitigating steps, especially in relation to high risk processing activities  Assess yourself in the areas of consent and marketing.  Assess your compliance with data protection in the specific areas of information security policy and risk, mobile working, removable media, access controls and malware protection.  include physical security processes assess the compliance of your CCTV including the installation, management, operation, and public awareness and signage. Implement technical and organizational security measures appropriate to the risks presented The only technical controls mentioned in GDPR are encryption and pseudonymisation (de-identifying datawith a mechanism to re-identify if necessary) Clients may not need to notify data subjects about a breach if the personal data has been rendered “unintelligible to any person who is not authorised to access it, such as encryption”.
  7. Records management Develop records management policy and procedures When storing physical records, make sure they're secure in rest and in motion Outsourcing Records inventories Tracking and off-site storage Security and disposal of data Business continuity Record creation, storage and disposal, access, tracking and off-site storage.
  8. training process and awareness programs staff handbooks training material  key vendor contracts Third-party risk there are also significant risks which can and should be minimized through appropriate contractual clauses, as well as  by conducting due diligence on third party vendors, to ensure that those operating on behalf of your organization ( partners and service providers) are capable of operating in compliance with the GDPR. Audit existing supplier arrangements and update template RFP and procurement contracts  8. Consent of data subjects - • should be explicit It has to be opt in , not opt out and no response means no consent. Consent must also now be separable from other written agreements, is given before data is processed and should be as easily revoked as given. data subjects are informed that they have the right to withdraw consent at any time but that this will not affect the lawfulness of processing based on consent before its withdrawal; Consent is not the only legal basis for processing personal data though. When there is a legitimate interest involved, consent is given after the processing and even if the subject objects, the processing doesn’t stop.  9. Notifications to data subjects & data subject’s right to access, modify, delete, transfer data  The controller is obliged to respond to requests from the data subject without undue delay and at the latest within one month and to give reasons where the controller does not intend to comply with any such requests.  Determine if you work in a sector where exemptions are ………. By a EU member’s National legislation
  9. Focus on Preparedness for the inevitable YOUR INCIDENT RESPONSE PLAN to a malware attack: at first you should access the extention of the damage, in order to see if you can contain the attack and stop the spreading of the malware . Then triage question should be answered, like Whats affected, who did it, how did it happen, is it ongoing or an isolated incident .how critical is it, etc. There was a huge dbate about wether a ransomeware attack qualifies as a reportable breach incident. The conclusion was that YES A RANSOMEWARE ATTACK is a Reportable breach, but because every situation is fact based , there are few limited exceptions. Like Australian authorities already did, they will be guiding lines or mandatory provisions about when a data breach is always reportable. After a Data breach report, the regulators will examine
  10. 14