Diese Präsentation wurde erfolgreich gemeldet.
Die SlideShare-Präsentation wird heruntergeladen. ×

DPO Day Conference - Minimizing Privacy Risks

Anzeige
Anzeige
Anzeige
Anzeige
Anzeige
Anzeige
Anzeige
Anzeige
Anzeige
Anzeige
Anzeige
Anzeige

Hier ansehen

1 von 21 Anzeige

DPO Day Conference - Minimizing Privacy Risks

Minimising Privacy Risk from A Global DPO Perspective https://www.copenhagencompliance.com/2021/dpoday/agenda.html DPO, CISO, Controller or Processor? – (And the Risk Of Mixing Roles)
Minimising the Aggregate Privacy Risk Vs Contract Sharing
Using A Data Processor Modular DPIA And Data Flow
Leveraging Binding Corporate Rules as Data Processor
Prof. Hernan Huwyler, CPA, MBA

Minimising Privacy Risk from A Global DPO Perspective https://www.copenhagencompliance.com/2021/dpoday/agenda.html DPO, CISO, Controller or Processor? – (And the Risk Of Mixing Roles)
Minimising the Aggregate Privacy Risk Vs Contract Sharing
Using A Data Processor Modular DPIA And Data Flow
Leveraging Binding Corporate Rules as Data Processor
Prof. Hernan Huwyler, CPA, MBA

Anzeige
Anzeige

Weitere Verwandte Inhalte

Diashows für Sie (20)

Ähnlich wie DPO Day Conference - Minimizing Privacy Risks (20)

Anzeige

Weitere von Hernan Huwyler, MBA CPA (20)

Aktuellste (20)

Anzeige

DPO Day Conference - Minimizing Privacy Risks

  1. 1. Minimizing privacy risks From the DPO perspective Prof. Hernan Huwyler
  2. 2. The compliance think tank in the Nordics and beyond Certifications Compliance Privacy InfoSec Risk
  3. 3. The unclear ownership of privacy risks is still a major issue for GDPR compliance
  4. 4. DPO, CISO, CIO, CPO, COO and legal advisors
  5. 5. The roles to control privacy risks become uncoordinated when the GDPR implementation committees ended
  6. 6. Gaps in roles prevent a cost- efficient allocation of resources and creates blind spots
  7. 7. Unclear internal roles affect the efficiency of instructions, contractual requirements and due diligence of processors
  8. 8. The CISO monitors the risks on the confidentiality, integrity and availability of personal data
  9. 9. The DPO monitors the risks on the lack of GDPR compliance triggered by cyber and legal threats
  10. 10. CISO DPO Security policy Acceptable use Data classification Access control Loss prevention Privacy policy Subject requests ROPA inventory Consents Breach response Policy ownership
  11. 11. Desperate need for doers able to translate legal requirements into cyber controls, SOPs and technology
  12. 12. Joint and several liability Each joined controller is liable for the full GDPR requirements of a contract with the same data subject
  13. 13. Joint and several liability All privacy risks are assessed by each joined controller, even for the processing done by the partner
  14. 14. Solution Flow managers allow modular DPIAs to accelerate the completion
  15. 15. Solution Cyber security, business and legal experts complete different risk modules
  16. 16. Solution The approval flows are escalated to the DPO, the CRO and the contract owner
  17. 17. The binding corporate rules should cover the requirements, transfers and controls of data processing contracts
  18. 18. EU Customer Controller EU Company Processor Non EU Companies Intra group processors BCP-P Binding corporate rules for processors Transfer scheme EU Data subject
  19. 19. Non-EU intra-group processors should standardize and coordinate the execution of controls and access requests
  20. 20. @hewyler /hernanwyler mydailyexecutive.blogspot.com

×