france ix gdpr preparation and compliance
play

France-IX GDPR preparation and compliance Thierry Draveny 1 - PowerPoint PPT Presentation

France-IX GDPR preparation and compliance Thierry Draveny 1 France-IX General Meeting September 2018 Context and compliance scope at France-IX 2 France-IX General Meeting September 2018 Context The General Data Protection Regulation


  1. France-IX GDPR preparation and compliance Thierry Draveny 1 France-IX General Meeting September 2018

  2. Context and compliance scope at France-IX 2 France-IX General Meeting September 2018

  3. Context The General Data Protection Regulation (EU/2016/79) which came into effect the 25th of may 2018 : strengthens rights for individuals concerning their personal data ; implies new obligations for companies, as data controllers and/or processors. 3 France-IX General Meeting September 2018

  4. What is personal data ? Any information relating to a natural person (‘data subject’) Who can be identified directly or indirectly Full definition in article 4 of the GDPR 4 France-IX General Meeting September 2018

  5. GDPR compliance scope We identified within France-IX activities 3 general purposes for which personal data might be processed Infrastructure Customer care support, Human functioning sales & marketing ressources Data flow transfered Individual information Individual information by members about members and about France-IX employees through the France-IX’s infrastructure prospects employees 5 France-IX General Meeting September 2018

  6. GDPR compliance scope We analysed which processes might involve personal data YES , for customer care support, NO , for infrastructure sales & marketing, human ressources functioning France-IX doesn't extract any personal data Database : members & prospects, France-IX's employees. (eg. IP addresses) from flows crossing the Direct communication related to France-IX’s activities. infrastructure. Data flow is aggregated by Member Suppliers : Network Operations Center (NOC), Data Center (MAC of the router) in order to provide statistics. and operators (dark fibre). 6 France-IX General Meeting September 2018

  7. Compliance works in progress 7 France-IX General Meeting September 2018

  8. Compliance works in progress Processes of personal data Privacy and policy will be published on Record of processing activities for the website. database, including security policy. GDPR’s mentions will be added to Data processor agreements with our communication supports, including request suppliers and contact forms. Contact dedicated for individuals who want to exercise their rights over their personal data. 8 France-IX General Meeting September 2018

  9. Focus on ‘members & prospects database’ Limited purposes Execution of the contracts Direct communication related to France-IX activities 9 France-IX General Meeting September 2018

  10. Focus on ‘members & prospects database’ « Dataminimization » Gender, first name and surname Position in the company Postal address of the company Phone number email address Logs from various web portals (eg. https://tools.franceix.net/) 10 France-IX General Meeting September 2018

  11. Focus on ‘members & prospects database’ Data retention period Limited to the period for which the personal data are processed. Erasure of the data when asked by and individual. No data transfer outside EU 11 France-IX General Meeting September 2018

  12. Summary GDPR’s key points Compliance works in progress Principles (art 5 to 11) § Accountability § Lawfullness of processing § Dataminimization § Limited retention of data Records of processing activities § ... Rights of the ‘data subject’ (art 12 to 23) Data processor agreements § Transparency and access to personal data § Rectification, erasure and restriction Privacy and security policy § Right to object Obligations of the controller and processor (art 24 to 39) § Responsabilities § Record of processing activities § Security § Data protection officer 12 France-IX General Meeting September 2018

  13. THANK YOU FOR YOUR ATTENTION 13 France-IX General Meeting September 2018

Recommend


More recommend