SlideShare ist ein Scribd-Unternehmen logo
1 von 17
Data privacy in 2017 – 2018
Powered by Global Markets - EY Knowledge
Bulgaria
March, 2017
Page 2
Personal data in digital world
IAB Forum – Data Privacy
Page 3
Security and Data Privacy within business environment
Source – from Ernst &Young’s Insights on IT Risks – Evolving IT risk landscape report
Rise of
online
fraud
Payment Card
Industry data
security standard
IAB Forum - Data Privacy
Page 4
High value data identification for a business unit
Corporate data
► Price/cost lists
► Target customer lists
► New designs
► Source code
► Intellectual property
► Pending media releases (not yet cleared for
release)
Transaction data
► Bank payments
► B2B orders
► Vendor data
► Sales volumes
► Purchase power
► Revenue potential
► Sales projections
Customer data
► Customer list
► Spending habits
► Contact details
► User preference
► Product customer profile
► Payment status
► Contact history
Personal data
► Full name
► Birthday, birthplace
► Biometric data
► Genetic information
► Credit /Debit card numbers
► National identification number
IAB Forum – Data Privacy
Page 5
Threats and results
Considering what could go wrong is important for understanding what needs to be done to effectively manage
and protect personal data
Could Result In…
► Identity theft (customers, employees,
business partners)
► Brand and reputation damage
► Litigation
► Regulatory action
► Direct financial loss
► Loss of market value
► Loss of consumer and business
partner confidence
► Becoming the example of what could
go wrong
Common Threats
► Lost or stolen media
► Over-sharing of personal
information
► Good intentions but misused data
► Third party service provider
weaknesses
► Web site compromise
► Hackers (inside and outside)
► Unwanted marketing
communications (telephone, email)
► Fraudulent transactions
► Social engineering, including
phishing
IAB Forum - Data Privacy
Page 6
2015 Top 10 Data incidents
Affected persons: 111,022,154
Source: http://healthitsecurity.com/news/healthcare-data-breaches-top-reported-data-security-
incident
Page 7
Some statistics
In top 10 for 2015, the data privacy incidents compromised
personal data owned by 111,022,154 people (SUA)
The most affected industries:
 Health care– 26.9% (60% lost of storage devices; 7% external
attacks)
 Education– 16,8%
 Governmental institutions– 15,9%
 Retail – 12,5%
Source: http://healthitsecurity.com/news/top-10-healthcare-data-breaches-of-2015
“Researchers found that more cybercriminals used more zero-day attacks, including phishing
scams and ransomware, in 2015.
The number of zero-day vulnerabilities in 2015 increased by 125 percent from a year ago.
Meanwhile, 430 million new malware variants were found in 2015.”
Page 8
Statistics
Breaking Down the H1 2016 Data Breach Statistics*:
► 3.04 million records compromised every day
► 126,936 records compromised every hour
► 2,116 records compromised every minute
► 35 records compromised every second
► The 554 million compromised records also represents a 31%
increase from the previous six months, when 424 million records
were lost or stolen.
Source: the Breach Level Index on http://breachlevelindex.com/#sthash.VsBJEWXR.dpuf
Type of data breaches are various:
► Identity theft
► Unauthorized access to the systems, databases
► Account access
► Financial access
► Accidental loss
► Theft of mobile devises (laptops, etc)
Eurobarometer: 71% of the interviewed persons accepted that sharing their
personal data is part of the digital era, being “the rule” of their modern life. Just 2% stated
that they never provide their data for an online service!
Page 9
Legislative Framework
Page 10
European Union Legislative Framework
► Directive (EU) 1995/46*** on the protection of individuals with regard to the processing of personal data and on
the free movement of such data (repealed by GDPR – 25th of May, 2018)
► Directive (EU) 2002/58 concerning the processing of personal data and the protection of privacy in the electronic
communications sector
► European Commission on contractual clauses / transfer to third countries
► Directive (EU) 2016/680 on the protection of natural persons with regard to the processing of personal data by
competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or
the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework
Decision 2008/977/JHA. / to be implemented by 6th of May 2018
► EU General Regulation on Data Privacy 679/2016 on the protection of natural persons with regard to the
processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
IAB Forum - Data Privacy
Page 11
Implementation of the new EU General Regulation on Data Privacy!
► Cooperation of the national data privacy authorities (DPAs)
 One stop shop mechanism
 Common Investigations
 No need for mutual assistance conventions
► Harmonization of the flows: registries vs. data processing notification
► Privacy Impact Assessment
► Incident response plan: 72 hour for DPAs notification
► All data privacy requirements must be implemented and tested by 2018
 Data privacy rights to be fully observed (internal controls for consent, information, processes
and procedures, remediation measures, contractual clauses, etc.)
 Security and confidentiality protocols to be implemented (data classification; corporate
governance, record keeping), etc.
► In 2018, the applicable fines increase up to Euro 10 – 20 mill. / 2-4% world
wide turnover in case of undertakings
► All the data controllers and data processors have the legal obligation
to be able to demonstrate the compliance of processing activities!
IAB Forum - Data Privacy
GDPR applies
directly in all EU
member states
Principle of
accountability
All data controllers
and processors
must comply with it!
Page 12
Data Privacy Program
Page 13 IAB Forum – Data Privacy
► Determine if your information security and data protection program provides adequate protection for personal information
throughout your business units
► Identify data categories and information and privacy compliance requirements
► Inventory the location and use of personal information across the enterprise
► Run the gap analysis asap
► Identify your partners / third parties
► Define privacy and data protection requirements for third parties, and a process that involves periodic and
ongoing assurance
► Review the regulatory changes in the countries in which you transfer personal data
► Review your contracts / data processing agreements
► Integrate privacy considerations in significant business initiatives
► Consider the privacy impact resulting from the use of new technologies and new business partners
► Consider whether your privacy staff is still equipped to deal with the organization’s key risks and compliance obligations, and
see if your privacy procedures and training are effective in guiding employees on the appropriate use of personal data
► Establish a program to periodically reassess the accuracy of the personal data and privacy and security requirements
What next? To do list
Page 14
1 2 3
MajorSteps
4
Risk assessment
• An assessment of the systems and
personal data collections should be
reviewed – end to end process, from
the collection to the retention stages,
also including the international
transfer cases;
• Determine the alignment of existing
practices with the organization’s
privacy obligations and regulatory
compliance requirements.
Policies and procedures
• Based on step 1, set up and / or
adjust a series of policies of
procedures, such as but not limited
to: data classification framework,
code of conduct, binding corporate
rules, various other internal working
procedures and instructions;
Systems and security
• Develop the flow of processing
personal data in the IT systems and
related databases, considering the
following areas of interest:
• Data classification;
• Usage rights;
• Approval management;
• Data storage and transfer;
• Privacy by default / by design.
Support
• Internal controls implementation
• Policies and procedures
• Consultation desk
Contractual clauses for
partnerships
• Controller – processor relationship.
Records
• The processing of personal data
should be recorded in line with the
purpose, processors, etc.
Training
• Train the trainer / workshops /
employees training.
Complaint resolution
• Data subjects have the right to
object, access their data, ask for
personal data rectification;
• The answer should be submitted in
time.
Incident response
• The client should report the incidents
in due time and the measures taken
should diminish the effects
Management / organization
• Data privacy officer / organization
should be in place (or entities which
process personal data on a large
scale, including public institutions).
Assess Develop Implement Monitor
Data Privacy Program: EY overall approach
IAB Forum - Data Privacy
Page 15
Matrices of Risks
► Regulations
► Likelihood of occurrence
Consequence and operational impact gross
► Existing policies
► Remediation measures:
 Policies and work instructions,
 Confidentiality agreements, net
 Communication of the guidelines,
 Operational audits,
 Training
► Re-assessments.
Assess annually the identified risks
Page 16
Recommendations:
► Gap Assessment – GDPR
► Privacy Impact Assessment
► Third Party relationship: specific contractual clauses on
parties’ responsibility
► Incident Response Plan
► Remedies for data loss / cost for recovery
 The compensation and the liability cap
 Consequential damages / lack of profit to be excluded
 Insurance coverage, if the case
 Certification mechanism
IAB Forum - Data Privacy
Page 17
THANK YOU!
Maria Maxim | Senior Manager | Fraud Investigation & Dispute Service
Ernst & Young S.R.L.
Bucharest Tower Center Building, 22 Floor, 15-17 Ion Mihalache Blvd., Bucharest, 011171, Sector 1,
Romania
Office: +40214024000 | Fax: +40213104965 | maria.maxim@ro.ey.com
Mobile: +40799098594
Website: http://www.ey.com
IAB Forum - Data Privacy

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17Data Protection Seminar_GDPR_ISOLAS_26-06-17
Data Protection Seminar_GDPR_ISOLAS_26-06-17
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
Data Protection Forum Brussels 230517 - Implementing GDPR
Data Protection Forum Brussels 230517 - Implementing GDPRData Protection Forum Brussels 230517 - Implementing GDPR
Data Protection Forum Brussels 230517 - Implementing GDPR
 
Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?Findability Day 2016 - What is GDPR?
Findability Day 2016 - What is GDPR?
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
12 steps to gdpr compliance unleashed
12 steps to gdpr compliance   unleashed12 steps to gdpr compliance   unleashed
12 steps to gdpr compliance unleashed
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19Niall Rooney FD Event 05.09.19
Niall Rooney FD Event 05.09.19
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...GDPR The New Data Protection Law coming into effect May 2018. What does it me...
GDPR The New Data Protection Law coming into effect May 2018. What does it me...
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
A Pratical Guide to GDPR - F.Coin
A Pratical Guide to GDPR - F.CoinA Pratical Guide to GDPR - F.Coin
A Pratical Guide to GDPR - F.Coin
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 

Ähnlich wie Data Privacy Program – a customized solution for the new EU General Regulation on Data Protection

Big_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedBig_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_published
Shradha Verma
 
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
emermell
 
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
David Kearney
 

Ähnlich wie Data Privacy Program – a customized solution for the new EU General Regulation on Data Protection (20)

Keep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR SuccessKeep Calm and Comply: 3 Keys to GDPR Success
Keep Calm and Comply: 3 Keys to GDPR Success
 
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to SuccessAddressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
Addressing the EU GDPR & New York Cybersecurity Requirements: 3 Keys to Success
 
The Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and ProtectionThe Future of the Modern Workplace Event 2019 - Data Security and Protection
The Future of the Modern Workplace Event 2019 - Data Security and Protection
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
Brussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACKBrussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACK
 
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
 
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy RiskAssessing Risk: How Organizations Can Proactively Manage Privacy Risk
Assessing Risk: How Organizations Can Proactively Manage Privacy Risk
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
eu-market-access-gdpr-fundamentals-by-risk-associates
eu-market-access-gdpr-fundamentals-by-risk-associateseu-market-access-gdpr-fundamentals-by-risk-associates
eu-market-access-gdpr-fundamentals-by-risk-associates
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
Big data analytics for life insurers
Big data analytics for life insurersBig data analytics for life insurers
Big data analytics for life insurers
 
Big_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_publishedBig_data_analytics_for_life_insurers_published
Big_data_analytics_for_life_insurers_published
 
Big Risks Requires Big Data Thinking
Big Risks Requires Big Data ThinkingBig Risks Requires Big Data Thinking
Big Risks Requires Big Data Thinking
 
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
Making ‘Big Data’ Your Ally – Using data analytics to improve compliance, due...
 
[AIIM18] GDPR: whose job is it now? - Paul Lanois
[AIIM18] GDPR: whose job is it now? - Paul Lanois[AIIM18] GDPR: whose job is it now? - Paul Lanois
[AIIM18] GDPR: whose job is it now? - Paul Lanois
 
Information Risk Management Overview
Information Risk Management OverviewInformation Risk Management Overview
Information Risk Management Overview
 
IASA ey deck presentation
IASA ey deck presentationIASA ey deck presentation
IASA ey deck presentation
 
NextLevel Cyber Security Executive Briefing
NextLevel Cyber Security Executive BriefingNextLevel Cyber Security Executive Briefing
NextLevel Cyber Security Executive Briefing
 
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
 

Mehr von IAB Bulgaria

Mehr von IAB Bulgaria (20)

Топ 100 рекламодатели в интернет
Топ 100 рекламодатели в интернетТоп 100 рекламодатели в интернет
Топ 100 рекламодатели в интернет
 
IAB Ad ex report 2018
IAB Ad ex report 2018 IAB Ad ex report 2018
IAB Ad ex report 2018
 
IAB MIXX Awards 2017 -финалисти
IAB MIXX Awards 2017 -финалистиIAB MIXX Awards 2017 -финалисти
IAB MIXX Awards 2017 -финалисти
 
AdEx Report for Bulgarian Industry
 AdEx Report for Bulgarian Industry AdEx Report for Bulgarian Industry
AdEx Report for Bulgarian Industry
 
Digital Case Study White Paper 2017
 Digital Case Study White Paper 2017 Digital Case Study White Paper 2017
Digital Case Study White Paper 2017
 
Technology environment, programmatic strategies – where we are and where are ...
Technology environment, programmatic strategies – where we are and where are ...Technology environment, programmatic strategies – where we are and where are ...
Technology environment, programmatic strategies – where we are and where are ...
 
Top 100 Bulgarian Advertisers
Top 100 Bulgarian AdvertisersTop 100 Bulgarian Advertisers
Top 100 Bulgarian Advertisers
 
Presentation, Frederik Strauss, Yeildbird
Presentation, Frederik Strauss, YeildbirdPresentation, Frederik Strauss, Yeildbird
Presentation, Frederik Strauss, Yeildbird
 
Презентация на Гражданите (grajdanite.bg) за MIXX 2016
Презентация на Гражданите (grajdanite.bg) за MIXX 2016Презентация на Гражданите (grajdanite.bg) за MIXX 2016
Презентация на Гражданите (grajdanite.bg) за MIXX 2016
 
Презентация на Катя Тодорова за наградите MIXX 2016
Презентация на Катя Тодорова за наградите MIXX 2016Презентация на Катя Тодорова за наградите MIXX 2016
Презентация на Катя Тодорова за наградите MIXX 2016
 
Презентация на Георги Малчев за MIXX 2016
Презентация на Георги Малчев за MIXX 2016Презентация на Георги Малчев за MIXX 2016
Презентация на Георги Малчев за MIXX 2016
 
Digital case studies white paper 2016
Digital case studies white paper 2016Digital case studies white paper 2016
Digital case studies white paper 2016
 
Iab digital run call for cаse studies
Iab digital run   call for cаse studiesIab digital run   call for cаse studies
Iab digital run call for cаse studies
 
Бъдещето на монетизацията в медиите (панелна дискусия) Ниво на AdBlockers в Б...
Бъдещето на монетизацията в медиите (панелна дискусия) Ниво на AdBlockers в Б...Бъдещето на монетизацията в медиите (панелна дискусия) Ниво на AdBlockers в Б...
Бъдещето на монетизацията в медиите (панелна дискусия) Ниво на AdBlockers в Б...
 
Video in the digital marketing
Video in the digital marketingVideo in the digital marketing
Video in the digital marketing
 
Adex: Oбемът на дигиталния пазар в България за 2015, сплит между отделните ре...
Adex: Oбемът на дигиталния пазар в България за 2015, сплит между отделните ре...Adex: Oбемът на дигиталния пазар в България за 2015, сплит между отделните ре...
Adex: Oбемът на дигиталния пазар в България за 2015, сплит между отделните ре...
 
Digital trends and habits of the people 2016
Digital trends and habits of the people 2016Digital trends and habits of the people 2016
Digital trends and habits of the people 2016
 
The future of shopping is happening now! Digital Payments
The future of shopping is happening now! Digital PaymentsThe future of shopping is happening now! Digital Payments
The future of shopping is happening now! Digital Payments
 
IAB Europe Mobile Audit Report
IAB Europe Mobile Audit Report IAB Europe Mobile Audit Report
IAB Europe Mobile Audit Report
 
IAB FORUM 2015 ТОП 100 рекламодатели в Интернет за 2014 и рекламни дялове по...
IAB FORUM 2015  ТОП 100 рекламодатели в Интернет за 2014 и рекламни дялове по...IAB FORUM 2015  ТОП 100 рекламодатели в Интернет за 2014 и рекламни дялове по...
IAB FORUM 2015 ТОП 100 рекламодатели в Интернет за 2014 и рекламни дялове по...
 

Kürzlich hochgeladen

₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
Diya Sharma
 

Kürzlich hochgeladen (20)

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
₹5.5k {Cash Payment}New Friends Colony Call Girls In [Delhi NIHARIKA] 🔝|97111...
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls Dubai
 
Enjoy Night⚡Call Girls Samalka Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Samalka Delhi >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Samalka Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Samalka Delhi >༒8448380779 Escort Service
 
VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 

Data Privacy Program – a customized solution for the new EU General Regulation on Data Protection

  • 1. Data privacy in 2017 – 2018 Powered by Global Markets - EY Knowledge Bulgaria March, 2017
  • 2. Page 2 Personal data in digital world IAB Forum – Data Privacy
  • 3. Page 3 Security and Data Privacy within business environment Source – from Ernst &Young’s Insights on IT Risks – Evolving IT risk landscape report Rise of online fraud Payment Card Industry data security standard IAB Forum - Data Privacy
  • 4. Page 4 High value data identification for a business unit Corporate data ► Price/cost lists ► Target customer lists ► New designs ► Source code ► Intellectual property ► Pending media releases (not yet cleared for release) Transaction data ► Bank payments ► B2B orders ► Vendor data ► Sales volumes ► Purchase power ► Revenue potential ► Sales projections Customer data ► Customer list ► Spending habits ► Contact details ► User preference ► Product customer profile ► Payment status ► Contact history Personal data ► Full name ► Birthday, birthplace ► Biometric data ► Genetic information ► Credit /Debit card numbers ► National identification number IAB Forum – Data Privacy
  • 5. Page 5 Threats and results Considering what could go wrong is important for understanding what needs to be done to effectively manage and protect personal data Could Result In… ► Identity theft (customers, employees, business partners) ► Brand and reputation damage ► Litigation ► Regulatory action ► Direct financial loss ► Loss of market value ► Loss of consumer and business partner confidence ► Becoming the example of what could go wrong Common Threats ► Lost or stolen media ► Over-sharing of personal information ► Good intentions but misused data ► Third party service provider weaknesses ► Web site compromise ► Hackers (inside and outside) ► Unwanted marketing communications (telephone, email) ► Fraudulent transactions ► Social engineering, including phishing IAB Forum - Data Privacy
  • 6. Page 6 2015 Top 10 Data incidents Affected persons: 111,022,154 Source: http://healthitsecurity.com/news/healthcare-data-breaches-top-reported-data-security- incident
  • 7. Page 7 Some statistics In top 10 for 2015, the data privacy incidents compromised personal data owned by 111,022,154 people (SUA) The most affected industries:  Health care– 26.9% (60% lost of storage devices; 7% external attacks)  Education– 16,8%  Governmental institutions– 15,9%  Retail – 12,5% Source: http://healthitsecurity.com/news/top-10-healthcare-data-breaches-of-2015 “Researchers found that more cybercriminals used more zero-day attacks, including phishing scams and ransomware, in 2015. The number of zero-day vulnerabilities in 2015 increased by 125 percent from a year ago. Meanwhile, 430 million new malware variants were found in 2015.”
  • 8. Page 8 Statistics Breaking Down the H1 2016 Data Breach Statistics*: ► 3.04 million records compromised every day ► 126,936 records compromised every hour ► 2,116 records compromised every minute ► 35 records compromised every second ► The 554 million compromised records also represents a 31% increase from the previous six months, when 424 million records were lost or stolen. Source: the Breach Level Index on http://breachlevelindex.com/#sthash.VsBJEWXR.dpuf Type of data breaches are various: ► Identity theft ► Unauthorized access to the systems, databases ► Account access ► Financial access ► Accidental loss ► Theft of mobile devises (laptops, etc) Eurobarometer: 71% of the interviewed persons accepted that sharing their personal data is part of the digital era, being “the rule” of their modern life. Just 2% stated that they never provide their data for an online service!
  • 10. Page 10 European Union Legislative Framework ► Directive (EU) 1995/46*** on the protection of individuals with regard to the processing of personal data and on the free movement of such data (repealed by GDPR – 25th of May, 2018) ► Directive (EU) 2002/58 concerning the processing of personal data and the protection of privacy in the electronic communications sector ► European Commission on contractual clauses / transfer to third countries ► Directive (EU) 2016/680 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA. / to be implemented by 6th of May 2018 ► EU General Regulation on Data Privacy 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC IAB Forum - Data Privacy
  • 11. Page 11 Implementation of the new EU General Regulation on Data Privacy! ► Cooperation of the national data privacy authorities (DPAs)  One stop shop mechanism  Common Investigations  No need for mutual assistance conventions ► Harmonization of the flows: registries vs. data processing notification ► Privacy Impact Assessment ► Incident response plan: 72 hour for DPAs notification ► All data privacy requirements must be implemented and tested by 2018  Data privacy rights to be fully observed (internal controls for consent, information, processes and procedures, remediation measures, contractual clauses, etc.)  Security and confidentiality protocols to be implemented (data classification; corporate governance, record keeping), etc. ► In 2018, the applicable fines increase up to Euro 10 – 20 mill. / 2-4% world wide turnover in case of undertakings ► All the data controllers and data processors have the legal obligation to be able to demonstrate the compliance of processing activities! IAB Forum - Data Privacy GDPR applies directly in all EU member states Principle of accountability All data controllers and processors must comply with it!
  • 13. Page 13 IAB Forum – Data Privacy ► Determine if your information security and data protection program provides adequate protection for personal information throughout your business units ► Identify data categories and information and privacy compliance requirements ► Inventory the location and use of personal information across the enterprise ► Run the gap analysis asap ► Identify your partners / third parties ► Define privacy and data protection requirements for third parties, and a process that involves periodic and ongoing assurance ► Review the regulatory changes in the countries in which you transfer personal data ► Review your contracts / data processing agreements ► Integrate privacy considerations in significant business initiatives ► Consider the privacy impact resulting from the use of new technologies and new business partners ► Consider whether your privacy staff is still equipped to deal with the organization’s key risks and compliance obligations, and see if your privacy procedures and training are effective in guiding employees on the appropriate use of personal data ► Establish a program to periodically reassess the accuracy of the personal data and privacy and security requirements What next? To do list
  • 14. Page 14 1 2 3 MajorSteps 4 Risk assessment • An assessment of the systems and personal data collections should be reviewed – end to end process, from the collection to the retention stages, also including the international transfer cases; • Determine the alignment of existing practices with the organization’s privacy obligations and regulatory compliance requirements. Policies and procedures • Based on step 1, set up and / or adjust a series of policies of procedures, such as but not limited to: data classification framework, code of conduct, binding corporate rules, various other internal working procedures and instructions; Systems and security • Develop the flow of processing personal data in the IT systems and related databases, considering the following areas of interest: • Data classification; • Usage rights; • Approval management; • Data storage and transfer; • Privacy by default / by design. Support • Internal controls implementation • Policies and procedures • Consultation desk Contractual clauses for partnerships • Controller – processor relationship. Records • The processing of personal data should be recorded in line with the purpose, processors, etc. Training • Train the trainer / workshops / employees training. Complaint resolution • Data subjects have the right to object, access their data, ask for personal data rectification; • The answer should be submitted in time. Incident response • The client should report the incidents in due time and the measures taken should diminish the effects Management / organization • Data privacy officer / organization should be in place (or entities which process personal data on a large scale, including public institutions). Assess Develop Implement Monitor Data Privacy Program: EY overall approach IAB Forum - Data Privacy
  • 15. Page 15 Matrices of Risks ► Regulations ► Likelihood of occurrence Consequence and operational impact gross ► Existing policies ► Remediation measures:  Policies and work instructions,  Confidentiality agreements, net  Communication of the guidelines,  Operational audits,  Training ► Re-assessments. Assess annually the identified risks
  • 16. Page 16 Recommendations: ► Gap Assessment – GDPR ► Privacy Impact Assessment ► Third Party relationship: specific contractual clauses on parties’ responsibility ► Incident Response Plan ► Remedies for data loss / cost for recovery  The compensation and the liability cap  Consequential damages / lack of profit to be excluded  Insurance coverage, if the case  Certification mechanism IAB Forum - Data Privacy
  • 17. Page 17 THANK YOU! Maria Maxim | Senior Manager | Fraud Investigation & Dispute Service Ernst & Young S.R.L. Bucharest Tower Center Building, 22 Floor, 15-17 Ion Mihalache Blvd., Bucharest, 011171, Sector 1, Romania Office: +40214024000 | Fax: +40213104965 | maria.maxim@ro.ey.com Mobile: +40799098594 Website: http://www.ey.com IAB Forum - Data Privacy