david sumner eu gdpr p cism general data protection
play

David Sumner EU GDPR P CISM General Data Protection Regulation - PowerPoint PPT Presentation

General Data Protection Regulation David Sumner EU GDPR P CISM General Data Protection Regulation (GDPR) Why Supports a single digital market place Protect privacy & security of EU citizens in the digital age When


  1. General Data Protection Regulation David Sumner EU GDPR P CISM

  2. General Data Protection Regulation (GDPR) • Why • Supports a single digital market place • Protect privacy & security of EU citizens in the digital age • When • 25 th May 2018 • Who • Controllers & Processors of personal data of EU data subjects • Where • Inside the EU • Outside the EU • Restrictions on transfer of personal data outside the EU • Single supervisory authority

  3. General Data Protection Regulation (GDPR) • ICO International Strategy – clear statement of intent for a law of GDPR standards or higher for a post Brexit UK. • ”We will seek to explore the content of the UK as a ‘global data protection gateway’ – a country with a high standard of data protection law which is effectively interoperable with different legal systems that protect international flows of personal data.”

  4. General Data Protection Regulation (GDPR) What • Personal Data & Sensitive Personal Data • Fines • Rights • Principles • Consent • Accountability • Data Privacy Impact Assessment • Data Protection Officer • Data Breach Notification • Pseudonymisation

  5. General Data Protection Regulation (GDPR) Fines • Current ICO highest fine dispensed is £ 400 K • Fines are intended to be punitive and dissuasive • € 10 M or 2 % Global Group Turnover for breach of controller/processor duties e.g. failure to notify a breach of personal data • € 20 M or 4 % GlobalGroup Turnover for breach of GDPR requirements failure to uphold data subjects right or observe GDPR principles

  6. General Data Protection Regulation (GDPR) • It is simply too late to become fully compliant by 25 MAY 2018 • It is not too late to be compliant enough to – • Protect your business and your customers • Gain competitive advantage • Exploit opportunity • Gain protection from harsher fines etc. etc.

  7. General Data Protection Regulation (GDPR) How to Tackle It • MAP YOUR DATA • COMPLIANCE GAP ANALYSIS • RISK ASSESS (DPIA Lite) • RAISE AWARENESS • IMPLEMENT based on RATIONALE and RISK APPETITE

  8. General Data Protection Regulation (GDPR) QUESTIONS

Recommend


More recommend