SlideShare ist ein Scribd-Unternehmen logo
1 von 20
ENSURE GDPR COMPLIANCE WITH
LEANIX
(ADVANCED LEVEL)
22nd November 2018
Patrick Schober,
Customer Success Manager @LeanIX
WIFI: Leanix Code: EAconnectdays2
3
The General Data Protection Regulation, or GDPR
(EU 2016/679) is a regulation of the European Union introduced to
improve and unify personal data protection of individuals within the
European Union.
It entered into application in May 2018.
We help to understand and optimize IT Architectures:
Application Rationalization
4
Stay compliant and help preventing
penalty fees
GDPR in LeanIX
“GDPR drives maintenance of our LeanIX inventory. LeanIX provides GDPR a harmonized inventory as basis for
documentation”
- Andreas Bosch, Enterprise Architect, McKesson
Use GDPR as a driver for maintenance
of your LeanIX inventory
Safe operative costs (and nerves)
preparing a Data Protection Impact
Assessment (DPIA)
Only basic Fact Sheet Types are needed to start Application
Rationalization with LeanIX.
LeanIX Scope for handling
GDPR.
5
1.GDPR-Related Data maintained at
the Application Fact Sheet mainly
2.Relationships to Data Objects,
Interfaces, and IT Components need
to be established
3.Basic Configuration is recommended
to meet GDPR requirements
Provider
IT
Component
Project
User
Group
Data
Object
Technology
Architecture
Information System
Architecture
Business
Architecture
Tech.
Stack
Business
Capability
Process
Major Fact Sheet Types and relations for App Rationalization
Configuration recommended
Interface
Application*
*
Application as the central Fact Sheet to model GDPR in
LeanIX.
Fact Sheet Configuration
6
1.New Section on the Application Fact
Sheets
2.Capture information directly based
on GDPR-Regulation
 Reason for processing
 Legal Basis for processing
 General relevance of Application for
GDPR
Hint: Additional information like „Cross-Boarder
Transfer“ or „Category of external recipient“ might
be added to cover additional details.
We configure an additional Fact Sheet section upon your
request.
7
Related Data Objects (PII) and IT Components (e.g. Hosting
Services incl. location)
Relations you need for
your GDPR use case.
8
1.Relate the Data Objects to the
Applications, esp. Personal
Identifyable Information (PII) and tag
them accordingly
2.Relate Applications to the necessary
IT Components and maintain their
location (e.g. Hosting Service,
location: US)
3.Maintain Interfaces that are provided
by an Application and relate them to
the receiving Applications (e.g. using
SAP PO Integration)
Start with basic information and gather more details
iteratively.
9
Subscriptions will give you insights about responsibilities
from a technical and legal perspective.
Adding subscriptions
10
1.Make sure responsibility. For every
Application is clear
2.Differentiate responsibilities
introducing „Application Owner“
(Data Processor) or „Data Protection
Officer“
3.Subscriptions help you to have a
primary contact, if you need them
(e.g. as part of an official GDPR
“Procedure Index”)
Start with basic information and gather more details
iteratively.
11
Link all your relevant documents on the Fact Sheet to easily
hand them out them upon request.
Adding Documents
12
1.Link Document from your Content
Management System in LeanIX
2.Access all relevant data as you need
more detailed information (e.g. on
SLA, NDA, Security)
3.Hand out all relevant links as
regulatory bodies (IT Security,
Auditors, Revision, …) require to do
so
LeanIX makes it easy to access all relevant documents.
13
The survey helps you gathering additional GDPR related
data or access your experts to fill out your Fact Sheets.
Surveys-Power Features
14
1.Gather information that goes beyond
the attributes on the Fact Sheet
2.Enable experts to maintain Fact
Sheet Data in the survey – Low entry
barrier!
3.Send out „Standard Surveys“ on a
regular basis to apply with regulatory
requirements
Hint: We publish survey templates on an ongoing
basis in our product documentation and our public
github repository.
Entering data in reports massively lowers the entry barrier to
LeanIX for new stakeholders.
15*Survey available onhttps://github.com/leanix-public/surveys
The Application Landscape gives you the chance to plan the
compliance of your Applications in a business context.
Viewpoint: Enterprise /
Solution Architects
16
1.Where are Applications in use, that
are highly GDPR relevant?
2.Are the Applications still supported
by up-to-date technology?
1.What is the Data Flow of Personal
Identifyable Information?
2.Is my project handling Personal
Identifyable Data?
LeanIX provides you with an ad-hoc and easy to filter
Produdure Index.
Viewpoint: Data Privacy
Officer
17
1.Have all GDPR relevant Applications
available without any hassle for your
Data Protection Officers – They will
love it!
2.Hand out tables to auditors, revision,
and other stakeholders based on a
single-source inventory
3.Actively include your Data Privacy
Officer in your daily work
Create lists to hand out to your main GDPR stakeholders
without any hassle.
18
19
Key Take Aways
Data model easily
adaptable to capture GDPR
relevant information
Opens door to new strong
stakeholder and use case
Views and Reports that
answer audit-requests on
an ad-hoc basis
WIFI: Leanix
Code: EAconnectdays 20
THANK YOU!
Any Questions?

Weitere ähnliche Inhalte

Was ist angesagt?

A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...
A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...
A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...
Health Catalyst
 
Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...
Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...
Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...
Data Con LA
 

Was ist angesagt? (20)

Data Products and teams
Data Products and teamsData Products and teams
Data Products and teams
 
Simple. Friendly. Smart.
Simple. Friendly. Smart. Simple. Friendly. Smart.
Simple. Friendly. Smart.
 
Crema.co Pitch Deck
Crema.co Pitch DeckCrema.co Pitch Deck
Crema.co Pitch Deck
 
A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...
A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...
A Health Catalyst Overview: Learn How a Data First Strategy Can Drive Increas...
 
AI: Built to Scale
AI: Built to ScaleAI: Built to Scale
AI: Built to Scale
 
Three Must-Haves for a Successful Healthcare Data Strategy
Three Must-Haves for a Successful Healthcare Data StrategyThree Must-Haves for a Successful Healthcare Data Strategy
Three Must-Haves for a Successful Healthcare Data Strategy
 
SmartRecruiters Recruiting Platform
SmartRecruiters Recruiting PlatformSmartRecruiters Recruiting Platform
SmartRecruiters Recruiting Platform
 
Boost Customer Experience with UiPath and AWS Contact Center automation
Boost Customer Experience with UiPath and AWS Contact Center automationBoost Customer Experience with UiPath and AWS Contact Center automation
Boost Customer Experience with UiPath and AWS Contact Center automation
 
Platform-powered IT
Platform-powered ITPlatform-powered IT
Platform-powered IT
 
AI & Robotic Process Automation (RPA) to Digitally Transform Your Environment
AI & Robotic Process Automation (RPA) to Digitally Transform Your EnvironmentAI & Robotic Process Automation (RPA) to Digitally Transform Your Environment
AI & Robotic Process Automation (RPA) to Digitally Transform Your Environment
 
Business Pulse - Dual perspectives on the top 10 risks and opportunities 2013...
Business Pulse - Dual perspectives on the top 10 risks and opportunities 2013...Business Pulse - Dual perspectives on the top 10 risks and opportunities 2013...
Business Pulse - Dual perspectives on the top 10 risks and opportunities 2013...
 
Transforming the employee experience with Teams
Transforming the employee experience with TeamsTransforming the employee experience with Teams
Transforming the employee experience with Teams
 
Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...
Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...
Modernizing the Analytics and Data Science Lifecycle for the Scalable Enterpr...
 
Jade Global Digital Transformation & Cloud Consulting Partner - Overview
Jade Global Digital Transformation & Cloud Consulting Partner - OverviewJade Global Digital Transformation & Cloud Consulting Partner - Overview
Jade Global Digital Transformation & Cloud Consulting Partner - Overview
 
Coinbase Seed Round Pitch Deck
Coinbase Seed Round Pitch DeckCoinbase Seed Round Pitch Deck
Coinbase Seed Round Pitch Deck
 
AI Redefines Insurance
AI Redefines InsuranceAI Redefines Insurance
AI Redefines Insurance
 
Capgemini’s Connected Autonomous Planning
Capgemini’s Connected Autonomous PlanningCapgemini’s Connected Autonomous Planning
Capgemini’s Connected Autonomous Planning
 
Connected Analytics
Connected AnalyticsConnected Analytics
Connected Analytics
 
Enterprise Artificial Intelligence strategy
Enterprise Artificial Intelligence strategyEnterprise Artificial Intelligence strategy
Enterprise Artificial Intelligence strategy
 
AI: From Data to ROI
AI: From Data to ROIAI: From Data to ROI
AI: From Data to ROI
 

Ähnlich wie Ensure GDPR Compliance with LeanIX

Industrial internet big data german market study
Industrial internet big data german market studyIndustrial internet big data german market study
Industrial internet big data german market study
Business Finland
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter Jönsson
IBM Danmark
 

Ähnlich wie Ensure GDPR Compliance with LeanIX (20)

What is IHAN® project all about in technical matter?
What is IHAN® project all about in technical matter?What is IHAN® project all about in technical matter?
What is IHAN® project all about in technical matter?
 
HPE-Security update talk presented in Vienna to partners on 15th April 2016
HPE-Security update talk presented in Vienna to partners on 15th April 2016HPE-Security update talk presented in Vienna to partners on 15th April 2016
HPE-Security update talk presented in Vienna to partners on 15th April 2016
 
Webinar Industrial Data Space Association: Introduction and Architecture
Webinar Industrial Data Space Association: Introduction and ArchitectureWebinar Industrial Data Space Association: Introduction and Architecture
Webinar Industrial Data Space Association: Introduction and Architecture
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPR
 
Big data – A Review
Big data – A ReviewBig data – A Review
Big data – A Review
 
Endpoint Protection Platform Invent Youself/tutorialoutletdotcom
Endpoint Protection Platform Invent Youself/tutorialoutletdotcomEndpoint Protection Platform Invent Youself/tutorialoutletdotcom
Endpoint Protection Platform Invent Youself/tutorialoutletdotcom
 
Gdpr ccpa steps to near as close to compliancy as possible with low risk of f...
Gdpr ccpa steps to near as close to compliancy as possible with low risk of f...Gdpr ccpa steps to near as close to compliancy as possible with low risk of f...
Gdpr ccpa steps to near as close to compliancy as possible with low risk of f...
 
Manufacturing erp and industry 4.0 pdf
Manufacturing erp and industry 4.0 pdfManufacturing erp and industry 4.0 pdf
Manufacturing erp and industry 4.0 pdf
 
#GDPR Compliance - Data Minimization via ArchivePod
#GDPR Compliance - Data Minimization via ArchivePod#GDPR Compliance - Data Minimization via ArchivePod
#GDPR Compliance - Data Minimization via ArchivePod
 
Industrial internet big data german market study
Industrial internet big data german market studyIndustrial internet big data german market study
Industrial internet big data german market study
 
Industrial internet big data german market study
Industrial internet big data german market studyIndustrial internet big data german market study
Industrial internet big data german market study
 
Linking HPC to Data Management - EUDAT Summer School (Giuseppe Fiameni, CINECA)
Linking HPC to Data Management - EUDAT Summer School (Giuseppe Fiameni, CINECA)Linking HPC to Data Management - EUDAT Summer School (Giuseppe Fiameni, CINECA)
Linking HPC to Data Management - EUDAT Summer School (Giuseppe Fiameni, CINECA)
 
IT In Europe
IT In EuropeIT In Europe
IT In Europe
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter Jönsson
 
SAP insider GDPR compendium Hernan Huwyler
SAP insider GDPR compendium Hernan HuwylerSAP insider GDPR compendium Hernan Huwyler
SAP insider GDPR compendium Hernan Huwyler
 
ERP overview
ERP overviewERP overview
ERP overview
 
Erp
ErpErp
Erp
 
Data Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPRData Protection Officer Dashboard | GDPR
Data Protection Officer Dashboard | GDPR
 
Information Driven Enterprise for the Connected World
Information Driven Enterprise for the Connected WorldInformation Driven Enterprise for the Connected World
Information Driven Enterprise for the Connected World
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
 

Mehr von LeanIX GmbH

Mehr von LeanIX GmbH (20)

LeanIX Virtual Workspaces
LeanIX Virtual WorkspacesLeanIX Virtual Workspaces
LeanIX Virtual Workspaces
 
How to reduce complexity by segregating your data with Virtual Workspaces
How to reduce complexity by segregating your data with Virtual WorkspacesHow to reduce complexity by segregating your data with Virtual Workspaces
How to reduce complexity by segregating your data with Virtual Workspaces
 
Gartner EA: The Rise of Data-driven Architectures
Gartner EA: The Rise of Data-driven ArchitecturesGartner EA: The Rise of Data-driven Architectures
Gartner EA: The Rise of Data-driven Architectures
 
Application Harmonisation using Design Principles in LeanIX
Application Harmonisation using Design Principles in LeanIXApplication Harmonisation using Design Principles in LeanIX
Application Harmonisation using Design Principles in LeanIX
 
Effective EAM: whet your appetite & deliver solutions
Effective EAM: whet your appetite & deliver solutionsEffective EAM: whet your appetite & deliver solutions
Effective EAM: whet your appetite & deliver solutions
 
Lean EAM with the Microservices Add-on and the Signavio Integration
Lean EAM with the Microservices Add-on and the Signavio IntegrationLean EAM with the Microservices Add-on and the Signavio Integration
Lean EAM with the Microservices Add-on and the Signavio Integration
 
Next Level Enterprise Architecture
Next Level Enterprise ArchitectureNext Level Enterprise Architecture
Next Level Enterprise Architecture
 
Integration Architecture with the Data Flow
Integration Architecture with the Data FlowIntegration Architecture with the Data Flow
Integration Architecture with the Data Flow
 
LeanIX-ServiceNow Integration
LeanIX-ServiceNow IntegrationLeanIX-ServiceNow Integration
LeanIX-ServiceNow Integration
 
Custom Reports & Integrations with GraphQL
Custom Reports & Integrations with GraphQLCustom Reports & Integrations with GraphQL
Custom Reports & Integrations with GraphQL
 
LeanIX Inventory: Import & Export
LeanIX Inventory: Import & ExportLeanIX Inventory: Import & Export
LeanIX Inventory: Import & Export
 
Survey Add-on Showcase: Cloud Transformation
Survey Add-on Showcase: Cloud TransformationSurvey Add-on Showcase: Cloud Transformation
Survey Add-on Showcase: Cloud Transformation
 
The LeanIX Microservices Integration
The LeanIX Microservices IntegrationThe LeanIX Microservices Integration
The LeanIX Microservices Integration
 
LeanIX-Signavio Integration
LeanIX-Signavio IntegrationLeanIX-Signavio Integration
LeanIX-Signavio Integration
 
How to set up a Lean Standards Governance
How to set up a Lean Standards GovernanceHow to set up a Lean Standards Governance
How to set up a Lean Standards Governance
 
Innovative API-Based LeanIX Enhancements
Innovative API-Based LeanIX EnhancementsInnovative API-Based LeanIX Enhancements
Innovative API-Based LeanIX Enhancements
 
Moving EA - from where we are to where we should be
Moving EA - from where we are to where we should beMoving EA - from where we are to where we should be
Moving EA - from where we are to where we should be
 
Is next generation EAM more than just agile IT planning?
Is next generation EAM more than just agile IT planning?Is next generation EAM more than just agile IT planning?
Is next generation EAM more than just agile IT planning?
 
Beyond CIO - Will there still be Architecture Management in 2025
Beyond CIO - Will there still be Architecture Management in 2025Beyond CIO - Will there still be Architecture Management in 2025
Beyond CIO - Will there still be Architecture Management in 2025
 
The Day After Tomorrow
The Day After TomorrowThe Day After Tomorrow
The Day After Tomorrow
 

Kürzlich hochgeladen

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Kürzlich hochgeladen (20)

Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 

Ensure GDPR Compliance with LeanIX

  • 1. ENSURE GDPR COMPLIANCE WITH LEANIX (ADVANCED LEVEL) 22nd November 2018 Patrick Schober, Customer Success Manager @LeanIX
  • 2. WIFI: Leanix Code: EAconnectdays2
  • 3. 3 The General Data Protection Regulation, or GDPR (EU 2016/679) is a regulation of the European Union introduced to improve and unify personal data protection of individuals within the European Union. It entered into application in May 2018.
  • 4. We help to understand and optimize IT Architectures: Application Rationalization 4 Stay compliant and help preventing penalty fees GDPR in LeanIX “GDPR drives maintenance of our LeanIX inventory. LeanIX provides GDPR a harmonized inventory as basis for documentation” - Andreas Bosch, Enterprise Architect, McKesson Use GDPR as a driver for maintenance of your LeanIX inventory Safe operative costs (and nerves) preparing a Data Protection Impact Assessment (DPIA)
  • 5. Only basic Fact Sheet Types are needed to start Application Rationalization with LeanIX. LeanIX Scope for handling GDPR. 5 1.GDPR-Related Data maintained at the Application Fact Sheet mainly 2.Relationships to Data Objects, Interfaces, and IT Components need to be established 3.Basic Configuration is recommended to meet GDPR requirements Provider IT Component Project User Group Data Object Technology Architecture Information System Architecture Business Architecture Tech. Stack Business Capability Process Major Fact Sheet Types and relations for App Rationalization Configuration recommended Interface Application* *
  • 6. Application as the central Fact Sheet to model GDPR in LeanIX. Fact Sheet Configuration 6 1.New Section on the Application Fact Sheets 2.Capture information directly based on GDPR-Regulation  Reason for processing  Legal Basis for processing  General relevance of Application for GDPR Hint: Additional information like „Cross-Boarder Transfer“ or „Category of external recipient“ might be added to cover additional details.
  • 7. We configure an additional Fact Sheet section upon your request. 7
  • 8. Related Data Objects (PII) and IT Components (e.g. Hosting Services incl. location) Relations you need for your GDPR use case. 8 1.Relate the Data Objects to the Applications, esp. Personal Identifyable Information (PII) and tag them accordingly 2.Relate Applications to the necessary IT Components and maintain their location (e.g. Hosting Service, location: US) 3.Maintain Interfaces that are provided by an Application and relate them to the receiving Applications (e.g. using SAP PO Integration)
  • 9. Start with basic information and gather more details iteratively. 9
  • 10. Subscriptions will give you insights about responsibilities from a technical and legal perspective. Adding subscriptions 10 1.Make sure responsibility. For every Application is clear 2.Differentiate responsibilities introducing „Application Owner“ (Data Processor) or „Data Protection Officer“ 3.Subscriptions help you to have a primary contact, if you need them (e.g. as part of an official GDPR “Procedure Index”)
  • 11. Start with basic information and gather more details iteratively. 11
  • 12. Link all your relevant documents on the Fact Sheet to easily hand them out them upon request. Adding Documents 12 1.Link Document from your Content Management System in LeanIX 2.Access all relevant data as you need more detailed information (e.g. on SLA, NDA, Security) 3.Hand out all relevant links as regulatory bodies (IT Security, Auditors, Revision, …) require to do so
  • 13. LeanIX makes it easy to access all relevant documents. 13
  • 14. The survey helps you gathering additional GDPR related data or access your experts to fill out your Fact Sheets. Surveys-Power Features 14 1.Gather information that goes beyond the attributes on the Fact Sheet 2.Enable experts to maintain Fact Sheet Data in the survey – Low entry barrier! 3.Send out „Standard Surveys“ on a regular basis to apply with regulatory requirements Hint: We publish survey templates on an ongoing basis in our product documentation and our public github repository.
  • 15. Entering data in reports massively lowers the entry barrier to LeanIX for new stakeholders. 15*Survey available onhttps://github.com/leanix-public/surveys
  • 16. The Application Landscape gives you the chance to plan the compliance of your Applications in a business context. Viewpoint: Enterprise / Solution Architects 16 1.Where are Applications in use, that are highly GDPR relevant? 2.Are the Applications still supported by up-to-date technology? 1.What is the Data Flow of Personal Identifyable Information? 2.Is my project handling Personal Identifyable Data?
  • 17. LeanIX provides you with an ad-hoc and easy to filter Produdure Index. Viewpoint: Data Privacy Officer 17 1.Have all GDPR relevant Applications available without any hassle for your Data Protection Officers – They will love it! 2.Hand out tables to auditors, revision, and other stakeholders based on a single-source inventory 3.Actively include your Data Privacy Officer in your daily work
  • 18. Create lists to hand out to your main GDPR stakeholders without any hassle. 18
  • 19. 19 Key Take Aways Data model easily adaptable to capture GDPR relevant information Opens door to new strong stakeholder and use case Views and Reports that answer audit-requests on an ad-hoc basis
  • 20. WIFI: Leanix Code: EAconnectdays 20 THANK YOU! Any Questions?