Preparing for the GDPR: Attaining and Demonstrating Compliance

Similar documents
GDPR Compliance Benchmarking: Measuring Accountability

GDPR Compliance Services. Data Privacy and Security Management Services

Everything you always wanted to know about privacy impact assessments but where afraid to ask

GDPR General Data Protection Regulation

EU General Data Protection Regulation in the digital age: Are you ready?

DATA PROTECTION OFFICER (DPO) Maria Maxim Partner Bucharest October 25, 2017

Getting to Accountability

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond

Preparing for the General Data Protection Regulation (GDPR)

Accountability under the GDPR: What does it mean for Boards & Senior Management?

EU General Data Protection Regulation: Are you ready?

GDPR is coming soon. Are you ready. Steven Ringelberg.

GDPR is coming in 108 days: Are you ready?

Preparing for GDPR: How Oracle Hospitality Can Help

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018

12 STEPS TO PREPARE FOR THE GDPR

GDPR Checklist. O - Organisation. P - Processing. T - Technology. I - Information. N - Next OVERVIEW. Your Personal Data

GDPR Partner Guide. Prepare Towards an Easy Compliance

EU General Data Protection Regulation, a new era in data protection

The Sage quick start guide for businesses

General Data Protection Regulation (GDPR)

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law.

GDPR a legal overview

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

General Data Protection Regulation

The GDPR: What does it mean for executive search?

The General Data Protection Regulation: What does it mean for you?

GDPR Service Information Sheet

Each of these areas of impact could have significant budgetary, IT, HR, governance, and communications implications:

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie

The GDPR and its requirements for implementing data protection impact assessments (DPIAs)

General Data Protection Regulation

EU General Data Protection Regulation (GDPR) A Point of View. For private circulation only. Risk Advisory

YOU RE ONLY AS STRONG AS YOUR WEAKEST LINK

What you need to know. about GDPR. as a Financial Broker. Sponsored by

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

Guidance on the General Data Protection Regulation: (1) Getting started

The EU General Data Protection Regulation

EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations. For private circulation only.

EU GENERAL DATA PROTECTION REGULATION

WHAT YOU NEED TO KNOW [WHITE PAPER] ABOUT GDPR HOW TO STAY COMPLIANT

The EU General Data Protection Regulation

The GDPR Are you ready?

Preparing for the General Data Protection Regulation (GDPR)

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

December 28, 2018, New Delhi, INDIA

COMPREHENSIVE LEGAL, TAX, ACCOUNTING AND AUDIT SERVICES

Briefing No. 2 GDPR. 1 mccann fitzgerald

What do companies need to do?

GDPR factsheet Key provisions and steps for compliance

WHITE PAPER EU General Data Protection Regulation Compliance

What does the GDPR mean for recruitment?

Countdown to GDPR: Challenges and Concerns

Protecting Your Personal Data Globally

GDPR The role of the Internal Audit Function

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER

IBM Collaboration Solutions Readiness for GDPR IBM Corporation

GDPR Factsheet - Key Provisions and steps for Compliance

GDPR: What Every MSP Needs to Know

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

GDPR in Early Years and Childcare settings. What s the connection? Data Protection

Getting Ready for the GDPR

Technical factsheet: General Data Protection Regulation (GDPR) April 2018

General Data Protection Regulation (GDPR) Frequently Asked Questions

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

THE EU GENERAL DATA PROTECTION REGULATION AND INTERNATIONAL AIRLINES SPECIAL UPDATE

GDPR Readiness: Role of the DPO

Accountability on the ground: Provisional guidance on documenting processing operations for EU institutions, bodies and agencies Summary

GENERAL DATA PROTECTION REGULATION

What in the World is GDPR? Imran Ahmad, Partner Miller Thomson LLP

With financial penalties of up to 4 percent of global annual turnover, are you up-to-date on the General Data Protection Regulation?

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities

Top 10 Data Protection Do s & Don ts in M&A

General Data Protection Regulation. Jim Sneddon GDPR-P, CISSP

General Data Protection Regulation. What should community energy organisations be doing to prepare?

Summary of General Data Regulation & Actions. Nationwide Coverage.

Paul Jordan Thursday 12 October,

Summary of General Data Regulation & Actions. Nationwide Coverage.

SAP and SAP Ariba Solution Support for GDPR Compliance

EU General Data Protection Regulation: are you ready?

The General Data Protection Regulation

Data Protection (internal) Audit prior to May (In preparation for that date)

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02]

A PRIMER on GDPR and MARKETING DATA PROTECTION BEST PRACTICES

WORLD REPORT >>> DATA PROTECTION

GDPR for Employers DUBLIN / BELFAST / LONDON / NEW YORK / SAN FRANCISCO / PALO ALTO

GDPR: An Evolution, Not a Revolution

Comments on Chapter IV Part I Controller and processor 25/08/2015 Page 1

Planning for the General Data Protection Regulation

Ready for GDPR? Five steps to turn compliance into your advantage

GLOBAL DATA PRIVACY SNAPSHOT 2018: How does your organisation compare?

OFFICIAL. Date 18 April 2018 Pacific Quay, Glasgow General Data Protection Regulation (GDPR) Police Scotland Preparedness Item Number 11.

General Data Protection Regulation

GDPR - Salon Guide Contents

EU General Data Protection Regulation (GDPR) Point of View for ERP and HRMS Operations. For private circulation only.

GDPR BEST PRACTICES ESSENTIAL PROCESSES TO MEET THREE KEY OBLIGATIONS

NEWSFLASH GDPR N 10 - New Data Protection Obligations

Transcription:

Preparing for the GDPR: Attaining and Demonstrating Compliance IAPP Privacy. Security. Risk. September 16, 2016. San Jose (CA) Copyright 2016 by Nymity Inc. All rights reserved. This document is provided as is without any express or implied warranty. This document does not constitute legal advice and if you require legal advice you should consult with an attorney. Forwarding this document outside your organization is prohibited. Reproduction or use of this document for commercial purposes requires the prior written permission of Nymity Inc.

Preparing for the GDPR: Attaining and Demonstrating Compliance The EU General Data Protection Regulation Understanding Accountability under the GDPR Operationalizing Accountability From Accountability to Compliance: Evidence Appropriate Technical and Organization Measures How Nymity helps Compliance in Practice Paul Breitbarth Nymity The Hague (NL) Joseph Alhadeff Oracle Washington D.C. (US) Andy Garner Nymity London (UK)

Introducing Nymity A Data Privacy Research & Solutions Company Focus: Dedicated to global data privacy compliance research Established: 2002 Offices: Toronto, Canada (HQ) London, UK The Hague, the Netherlands Bogota, Colombia Boulder, Colorado, USA Research: Inventor of several compliance methodologies & frameworks Funding: Partially funded by government R&D grants Software Solutions for the Privacy Office Privacy Management Solutions: Nymity Attestor Nymity Benchmarks Nymity Templates Nymity Planner Compliance Research Solutions: Nymity Research Nymity LawTables Nymity MofoNotes Nymity LatAm Nymity is a global data privacy compliance research company specializing in accountability, risk, and compliance software solutions for the Privacy Office. Nymity s suite of software solutions helps organizations attain, maintain, and demonstrate data privacy compliance.

EU General Data Protection Regulation What is the GDPR and why is it relevant? Regulation (EU) 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data One main data protection law for all EU Member States (until further notice including UK) Fully applicable from 25 May 2018 to all organizations processing personal data in the EU or when offering goods and services to people in the EU New financial penalties in case of non-compliance Maximum 20 million euro; or 4% worldwide annual turnover (whichever is higher)

EU General Data Protection Regulation Nymity s Approach to GDPR Compliance Checklist-based guidance to GDPR implementation is ubiquitous Nymity has a different approach that has been made available for free, based on many years of own research Focus on accountability and demonstrating compliance Not a one-off exercise No ticking boxes Going concern that requires attention on an ongoing basis

EU General Data Protection Regulation GDPR Compliance We envisage three types of organizations in 2018: 1. Those who are non-compliant 2. Those who are compliant 3. Those who are able to demonstrate ongoing compliance Snapshot of a given moment in time (compliant) vs. readiness to deal with changing circumstances because the fundamentals of the police are sound (ongoing compliance) Free tools available today at www.nymity.com/gdpr-toolkit More advanced solutions at a subscription basis

Nymity GDPR Compliance Toolkit

Understand Accountability under the GDPR Replacement of the obligation to register with DPA Understand your data processing operations on an ongoing basis: Both what and why Article 24 Responsibility of the Controller Article 5 Principles relating to personal data processing Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary. The controller shall be responsible for and be able to demonstrate compliance with paragraph 1 ( accountability ).

Accountability Cornerstone of the GDPR replaces notification obligation Accountability requires the need to show what you are doing (demonstrate compliance): To the supervisory authority To individuals Reduce risk of investigations and/or fines Quicker response to complaints and breaches - save time

Operationalizing Accountability: Structured Privacy Management Accountability Approach to Demonstrating Compliance Structured Privacy Management is embedding ongoing privacy management activities throughout the organization, resulting in the ability to demonstrate accountability and compliance with evidence. RESPONSIBILITY Privacy management activities have been implemented and are maintained on an ongoing basis. OWNERSHIP Privacy management activities are embedded throughout the organization within each function or business unit that processes personal data. EVIDENCE Documentation is produced as a result of a privacy management activity that can be used as Evidence of accountability and compliance.

Nymity Privacy Management Accountability Framework Accountability Approach to Demonstrating Compliance Privacy management activities are ongoing procedures, policies, measures, mechanisms, and other initiatives that impact the processing of personal data or that relate to compliance with privacy and data protection laws.

Evidence and Compliance Article 24 requires organizations to demonstrate that the processing of personal data is performed in compliance with this Regulation. Demonstrating compliance is a dialogue, the privacy office uses evidence to tell the story Not: Are we compliant right now? Instead: How do we comply on an ongoing basis?

Appropriate Technical and Organizational Measures Appropriate dependent on the specificities of an organization DPA Guidance can be expected in the coming years Don t wait Many measures are likely already part of your privacy program Document what is currently undocumented Best practices available Make sure you are ready to tell the story behind your privacy policy and illustrate it with supporting documents Nymity research tools accessible via IAPP Resources

Evidence and Compliance 39 of 99 Articles in the GDPR require Evidence to demonstrate compliance What about the others? Definitions Enforcement Actions Legal Obligations Codes of conduct

Evidence and Compliance Evidence of ongoing privacy management activities, embedded throughout the organization 55 mandatory privacy management activities

Nymity GDPR Compliance Toolkit

Nymity GDPR Compliance Toolkit Privacy Management Accountability Annotations

Nymity GDPR Compliance Toolkit Readiness Assessment Questions

Nymity GDPR Compliance Toolkit Roadmap for Demonstrable GDPR Compliance

Nymity Attestor Andy Garner Nymity

Compliance in practice Joseph Alhadeff Oracle

In Conclusion How Nymity Helps Free GDPR Compliance Toolkit Subscription-based Solutions Privacy Management Accountability Annotations Accountability Roadmap for Demonstrable Compliance Readiness Assessment Questions

Thank you paul.breitbarth@nymity.com @EuroPaulB +31.6.2493.6643 www.nymity.com/gdpr-toolkit Copyright 2016 by Nymity Inc. All rights reserved. This document is provided as is without any express or implied warranty. This document does not constitute legal advice and if you require legal advice you should consult with an attorney. Forwarding this document outside your organization is prohibited. Reproduction or use of this document for commercial purposes requires the prior written permission of Nymity Inc.