SlideShare a Scribd company logo
1 of 38
GDPR From the Trenches
Real-world examples of how companies
are approaching compliance
Magnus
Valmot
Ardoq
Simen
Breen
SANDS
Per
Franzén
Telia Norge
Ian
Stendera
Ardoq
Ask Questions
Simen Breen
SANDS
Seeking legal counsel to help you structure
compliance projects and assess risk
Simen Breen | Senior Lawyer | SANDS
How to start working with the GDPR?
 The nature of the GDPR
 The GDPR is not sector specific and there is no
threshold for the applicability
 Work in a structured way from the beginning, and
prioritize your efforts.
 Before you get down to the details of the GDPR you
 … need to know what you are doing with
personal data
 … need to know what to prioritize
There is no easy way out
 No one-size-fits-all strategy for GDPR compliance
 GDPR does not impact all businesses the same way,
and the starting position is different
 Most checklists are either incomplete or so vague that
they don’t really help.
 First steps should be the same:
 Establish a project team
 A mapping of personal data processing activities
 A mapping of compliance with existing requirements
on personal data protection and mapping of existing
policies, documentation etc.
Establish a project team
• A GDPR compliance project must have sufficient internal
resources to succeed
• Including the relevant people in your organization is key
• The project team needs to have basic knowledge of GDPR
and the reason for doing the mapping process
• The project manager and the team must be given
sufficient time and resources
• The project team should be able to make decisions
without time-consuming internal processes
• External advice if necessary; legal and information
security
Mapping the processing of personal data
• What types of personal data you process
• What are the purposes of the processing
• What are the legal bases for your processing activities
• What is the source of the data
• Where is the data and what systems are used
• Who is responsible for the processing and the data
systems
• How many persons does the processing comprise
• Use of data processors
• Transfer of data out of the EU/EEA
• Activities as data processor
• How to document this?
Mapping of your processing activities is
necessary for deciding how to go forward
• Knowing what processing of personal data the
business does is necessary to fulfill the requirements
in the GDPR
• Being able to understand which requirements are
relevant for your business
• Being able to concretize the principles etc. to
requirements
• Being able to make instructions and procedures that
actually work in practice
Mapping of your processing activities is
necessary for deciding how to go forward
• To be able to make priorities (if necessary)
• Priorities should not be made based on
assessing the article in itself
• Priorities should be made considering the
processing activities and the risks related
thereto
• Which processing operations are high risk
(to the rights and freedoms of natural
persons or legal risk) or business critical
Get it right from the start
• You have to structure your compliance
project based on your business
▪ Your data processing is the key
▪ Current compliance status is relevant –
depending on jurisdiction
• Even though the legal requirements are the
same for everyone, their practical effects
vary greatly
• A risk-based approach
Contact
Simen Evensen Breen
seb@sands.no
+47 928 20 300
+47 22 81 46 24
Per Franzén
Telia Norway
Experience from an
‟overwhelmed” project
manager
Per Franzén, Project Manager
EXPERIENCE FROM A PROJECT MANAGER: OVERWHELMING
AMOUNT OF GDPR TERMINOLOGY AND INSTRUCTIONS
Data minimizationIndividual Rights
Purpose
limitation
- Where do I start?
- Are there any guidelines?
- How does the GDPR
terminology and instructions
relate, or do they?
“REACHING COMPLIANCE LEVEL ON
GDPR IS KEY FOR OUR BUSINESS
AND THEREFORE
ONE OF OUR TOP PRIORITIES UNTIL
JUNE 2018.”
THIS IS THE GUIDANCE FROM TELIA CORPORATE
MANAGEMENT
GEM AMBITION
Business Vision and
Drivers - Privacy
GDPR Requirements
NO Legal Requirements
NO Privacy Strategy
Telia Company
Information Asset & Vendor
management –project,
GSO/ITAT
Processes, services
/products and IT
Asset and vendor
management
Telia Norge AS
EA and IT Governance –
GDPR NO
Business Architecture
Architecture Vision
Information and System
Architecture
Technology
Architecture
Telia Norge ASTelia Norge GDPR Compliance project
GDPR WORK STREAM
(in Group Security & Privacy)
Work stream management
Employee privacy
Awareness and com.
IT and enterprise
architecture
Stakeholders
DPO Norway
PSG GDPR Norway
Projects and activities
Project Vega - Security
NO IT EA Governance
NO IT Architecture project
Digital Telco initiative
Development
Trust as a Service
System Dev Teams
Line org
Orderchange
Project Management and business readiness
Run Project and
coordinate with Group
Align with other Projects
and activities in Norway
Prepare business to operate
new GDPR requirements
Transition planning and
execution
Opportunities and
solutions
Migration planning
Implementation
Goverance
Accountable (business)
B2B Management
B2C Management
OneCall Management
MyCall Management
Chess Management
HR Management
Procurement Management
Legal / Privacy Management
Technology Management
Security Management
Privacy Policies and Objectives
Input change (EPICs) - Observations
Privacy
Requirements
Guidance
Plans
Architecture principles
GSO
Deliverables
IN JANUARY 2017 I STARTED STRUCTURING THE PROJECT, AFTER WHICH WE
SPENT 2 MONTHS ON THE AS-IS ANALYSIS, AND 1 MONTH ON GAP ANALYSIS

GDPRITProject
AFTERWARDS I REALIZED THAT GDPR RIGHTS AND
PRINCIPLES ARE BASED ON THE MANAGEMENT OF
CUSTOMER AND EMPLOYEE PERSONAL DATA
Resources
OSS
BSS
Portal
Employee
Customer
Portal
GDPR
Individual rights
Authority
CLI
DataBase
PrivacyData
Goverance
Data
protection
principles
Telia Norge AS
Partners
Data Processors
Employee
Accountability
BUSINESS ARCHITECTURE – HOW DOES GDPR RELATE TO
TODAY’S OPERATIONS?
Accountability
Purposes
Legal
grounds
CustomerEmployee
Privacy
Data - BO
Business
Process Roles
Processes
Systems
OSS
BSS
Portal
IT System Roles
GDPR Individual
rights functionality
GDPR Data protection
principles functionality
Legal
requirement
TM Forum
eTOM L3 Performance of
contract
Legitimate
interests
Individual’s
consent
IT System Roles
in IdM
GDPR Privacy
Data
Will be defined by
GDPR Project
Will be defined by
GDPR Project
Will be defined by
GDPR Project
Privacy by
Design -
Policies
ACCOUNTABILITY IS CENTRAL –
TARGET ARCHITECTURE QUALITY SYSTEM (NOW BUILT IN ARDOQ)
Common Information
Model
Management
Data (AS-IS)
Accountability GDPR
GDPR law
Single consistent representation for
all management data
Management
Data (TO-BE)
Controls (Gap)
Observations
THE MODEL WE USE FOR WORKING IN ARDOQ
AS-IS
GDPR
compliance
TO-BE
TO-BE
TO-BE
Observations
OUR COMMON INFORMATION MODEL (CIM) IS
CENTRAL (WORK IN PROGRESS)
SOME EXAMPLE MODELS – EVERYTHING IS
CONNECTED IN OUR CIM 
HOW WE LINK THE REGULATION TO TELIA NORGE’S DAILY
OPERATIONS
WHY DO WE USE ARDOQ AND NOT
EXCEL?
1. Value adding
• When we first gather so much information, it should be useable across the organization
• Our IT solution to provide automated GDR Individual rights and related GDPR Data protection
principles are using Ardoq as a Policy/Rule engine
2. Maintenance – keeping information up-to-date continuously
• Ardoq has support for automating via integrations (input and output) and simplifies manual documentation
• We can automate Controls (Gaps) to verify compliance to GDPR (Observations)
• GDPR Training for Personell will be using data from Ardoq – will be personalized
3. Traceability
• We need to be able to trace how everything is connected and how they impact each other
• We now have an AS-IS status of the relations between data elements in the CIM and can run
predefined queries
Ian Stendera
Ardoq
Lessons Learned
Ian Stendera
VP of Customer Development at Ardoq
Lessons Learned
• Compliance is continuous
• Define realistic scope
• Think structured
Continuous Compliance
✓ ✓✓✓
May
2018
NOV
2018
May
2019
NOV
2018
Risk
Continuous Compliance
Document
Optimize
Implement
Analyze
Define Scope
Define Scope
Think Structured
VS
Think Structured:
handling attendees’ personal data
Org Unit
Personal
Data
Captured
Sensitive
Data?
Processing
Purpose
Source
Lawful
Basis
Systems
handling
personal
data
System
Owner
# of Data
Subjects
Transfered
externally?
Handled
outside of
EU?
Marketing
Name, Email,
Telephone
(optional),
company
No
Manage
Attendee
Registration
Eventbrite
webform
Consent
Eventbrite,
Prosperworks,
Excel
Marketing /
Sales
50
Yes, systems
are cloud
SaaS
solutions
No
Marketing
Name, Email,
Telephone
(optional),
company
No
Send Thank You
and
Presentations
Eventbrite
webform
? MailChimp Marketing 50
Yes, systems
are cloud
SaaS
solutions
No
Marketing
Name, Email,
Telephone
(optional),
company
No
Register for
Webinar
Eventbrite
webform
Consent Eventbrite Marketing 50
Yes, systems
are cloud
SaaS
solutions
No
Our mission:
Transform compliance
from a cost
To a
Value-adding process
Thank you
That’s all folks!
Questions?
Magnus
Valmot
Ardoq
Simen
Breen
SANDS
Per
Franzén
Telia Norge
Ian
Stendera
Ardoq
Thanks!
Stick around for
a Live Ardoq demo

More Related Content

What's hot

GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017Amarach Research
 
Splunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR ComplianceSplunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR ComplianceMarketingArrowECS_CZ
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by QualsysQualsys Ltd
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceIDERA Software
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranDr. Sami Zahran
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceMongoDB
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017Ray Bugg
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerCapgemini
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role HackerOne
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketingSpotler
 
GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?Samuel Pouyt
 
Doing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and doDoing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and doPatric Dahse
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...CIO Edge
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
12th July GDPR event slides
12th July GDPR event slides12th July GDPR event slides
12th July GDPR event slidesExponential_e
 

What's hot (20)

GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017GDPR and Irish SMEs May 2017
GDPR and Irish SMEs May 2017
 
Splunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR ComplianceSplunk: How Machine Data Supports GDPR Compliance
Splunk: How Machine Data Supports GDPR Compliance
 
GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and GovernanceGeek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
Geek Sync | Tackling Key GDPR Challenges with Data Modeling and Governance
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
Quick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami ZahranQuick Introduction to the EU GDPR by Sami Zahran
Quick Introduction to the EU GDPR by Sami Zahran
 
Using GDPR to Transform Customer Experience
Using GDPR to Transform Customer ExperienceUsing GDPR to Transform Customer Experience
Using GDPR to Transform Customer Experience
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017
 
Data- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offerData- and database security & GDPR: end-to-end offer
Data- and database security & GDPR: end-to-end offer
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role Everything you Need to Know about The Data Protection Officer Role
Everything you Need to Know about The Data Protection Officer Role
 
GDPR changes affect direct marketing
GDPR changes affect direct marketingGDPR changes affect direct marketing
GDPR changes affect direct marketing
 
GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?GDPR: Threat or Opportunity?
GDPR: Threat or Opportunity?
 
Doing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and doDoing Business in Europe? GDPR: What you need to know and do
Doing Business in Europe? GDPR: What you need to know and do
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
Digital Enterprise Festival Birmingham 13/04/17 - Ian West Cognizant VP Data ...
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
12th July GDPR event slides
12th July GDPR event slides12th July GDPR event slides
12th July GDPR event slides
 
GDPR Workshop
GDPR WorkshopGDPR Workshop
GDPR Workshop
 

Viewers also liked

GDPR en Cloud security
GDPR en Cloud securityGDPR en Cloud security
GDPR en Cloud securityDelta-N
 
DevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for Dummies
DevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for DummiesDevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for Dummies
DevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for DummiesDevOpsDays Riga
 
Will the GDPR Kibosh EU-US Discovery?
Will the GDPR Kibosh EU-US Discovery? Will the GDPR Kibosh EU-US Discovery?
Will the GDPR Kibosh EU-US Discovery? Logikcull.com
 
How is GDPR relevant for US companies
How is GDPR relevant for US companies How is GDPR relevant for US companies
How is GDPR relevant for US companies Patric Dahse
 
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]TrustArc
 
GDPR i offentlige anskaffelser
GDPR i offentlige anskaffelserGDPR i offentlige anskaffelser
GDPR i offentlige anskaffelserKjell Steffner
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideZymplify
 

Viewers also liked (8)

GDPR en Cloud security
GDPR en Cloud securityGDPR en Cloud security
GDPR en Cloud security
 
DevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for Dummies
DevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for DummiesDevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for Dummies
DevOpsDaysRiga 2017: Edward van Deursen - GDPR in DevOps for Dummies
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
Will the GDPR Kibosh EU-US Discovery?
Will the GDPR Kibosh EU-US Discovery? Will the GDPR Kibosh EU-US Discovery?
Will the GDPR Kibosh EU-US Discovery?
 
How is GDPR relevant for US companies
How is GDPR relevant for US companies How is GDPR relevant for US companies
How is GDPR relevant for US companies
 
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
Profiling, Big Data & Consent Under the GDPR [TrustArc Webinar Slides]
 
GDPR i offentlige anskaffelser
GDPR i offentlige anskaffelserGDPR i offentlige anskaffelser
GDPR i offentlige anskaffelser
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 

Similar to GDPR From the Trenches - Real-world examples of how companies are approaching compliance.

General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365 GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365 ayeshaurooj104
 
GDPR - Why it matters and how to make it Easy
GDPR - Why it matters and how to make it EasyGDPR - Why it matters and how to make it Easy
GDPR - Why it matters and how to make it EasyPaul McQuillan
 
CRMCS GDPR - Why it matters and how to make it Easy
CRMCS   GDPR - Why it matters and how to make it EasyCRMCS   GDPR - Why it matters and how to make it Easy
CRMCS GDPR - Why it matters and how to make it EasyPaul McQuillan
 
CIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieCIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieAndrew Pryor
 
Data privacy and security in uae
Data privacy and security in uaeData privacy and security in uae
Data privacy and security in uaeRishalHalid1
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers Gary Dodson
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anywayIRIS
 
Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?FactoVia
 
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRSolution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRIceberg Networks Corporation
 
What GDPR Means for App Analytics and Mobile Engagement
What GDPR Means for App Analytics and Mobile EngagementWhat GDPR Means for App Analytics and Mobile Engagement
What GDPR Means for App Analytics and Mobile EngagementLocalytics
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017Match-Maker Ventures
 
ABCON-AGM-2021-Final-2.pptx
ABCON-AGM-2021-Final-2.pptxABCON-AGM-2021-Final-2.pptx
ABCON-AGM-2021-Final-2.pptxHillaryObomighie
 
Toreon adding privacy by design in secure application development oss18 v20...
Toreon adding privacy by design in secure application development   oss18 v20...Toreon adding privacy by design in secure application development   oss18 v20...
Toreon adding privacy by design in secure application development oss18 v20...Sebastien Deleersnyder
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec
 
Six Key Components to Achieving GDPR Security Requirements
Six Key Components to Achieving GDPR Security RequirementsSix Key Components to Achieving GDPR Security Requirements
Six Key Components to Achieving GDPR Security RequirementsJeff Katanick
 
Building the Governance Ready Enterprise for GDPR Compliance
Building the Governance Ready Enterprise for GDPR ComplianceBuilding the Governance Ready Enterprise for GDPR Compliance
Building the Governance Ready Enterprise for GDPR ComplianceIndex Engines Inc.
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?Christiana Kozakou
 

Similar to GDPR From the Trenches - Real-world examples of how companies are approaching compliance. (20)

General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365 GDPR Compliance with Microsoft 365
GDPR Compliance with Microsoft 365
 
GDPR - Why it matters and how to make it Easy
GDPR - Why it matters and how to make it EasyGDPR - Why it matters and how to make it Easy
GDPR - Why it matters and how to make it Easy
 
CRMCS GDPR - Why it matters and how to make it Easy
CRMCS   GDPR - Why it matters and how to make it EasyCRMCS   GDPR - Why it matters and how to make it Easy
CRMCS GDPR - Why it matters and how to make it Easy
 
CIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James DuthieCIO WaterCooler Focus: GDPR - James Duthie
CIO WaterCooler Focus: GDPR - James Duthie
 
Data privacy and security in uae
Data privacy and security in uaeData privacy and security in uae
Data privacy and security in uae
 
What is CT- DPO.pdf
What is CT- DPO.pdfWhat is CT- DPO.pdf
What is CT- DPO.pdf
 
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers GDPR solutions (JS Event 28/2/18) | Greenlight Computers
GDPR solutions (JS Event 28/2/18) | Greenlight Computers
 
Whos role is it anyway
Whos role is it anywayWhos role is it anyway
Whos role is it anyway
 
Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?
 
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPRSolution Brief: Helping prepare for risk & compliance challenges for GDPR
Solution Brief: Helping prepare for risk & compliance challenges for GDPR
 
What GDPR Means for App Analytics and Mobile Engagement
What GDPR Means for App Analytics and Mobile EngagementWhat GDPR Means for App Analytics and Mobile Engagement
What GDPR Means for App Analytics and Mobile Engagement
 
MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017MMV Webinar 1. GDPR Perspectives. November 2017
MMV Webinar 1. GDPR Perspectives. November 2017
 
GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
 
ABCON-AGM-2021-Final-2.pptx
ABCON-AGM-2021-Final-2.pptxABCON-AGM-2021-Final-2.pptx
ABCON-AGM-2021-Final-2.pptx
 
Toreon adding privacy by design in secure application development oss18 v20...
Toreon adding privacy by design in secure application development   oss18 v20...Toreon adding privacy by design in secure application development   oss18 v20...
Toreon adding privacy by design in secure application development oss18 v20...
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year On
 
Six Key Components to Achieving GDPR Security Requirements
Six Key Components to Achieving GDPR Security RequirementsSix Key Components to Achieving GDPR Security Requirements
Six Key Components to Achieving GDPR Security Requirements
 
Building the Governance Ready Enterprise for GDPR Compliance
Building the Governance Ready Enterprise for GDPR ComplianceBuilding the Governance Ready Enterprise for GDPR Compliance
Building the Governance Ready Enterprise for GDPR Compliance
 
How does GDPR affect your business?
How does GDPR affect your business?How does GDPR affect your business?
How does GDPR affect your business?
 

Recently uploaded

Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...Rob Geurden
 
Best Angular 17 Classroom & Online training - Naresh IT
Best Angular 17 Classroom & Online training - Naresh ITBest Angular 17 Classroom & Online training - Naresh IT
Best Angular 17 Classroom & Online training - Naresh ITmanoharjgpsolutions
 
Large Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLarge Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLionel Briand
 
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingOpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingShane Coughlan
 
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...confluent
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...OnePlan Solutions
 
How to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationHow to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationBradBedford3
 
SoftTeco - Software Development Company Profile
SoftTeco - Software Development Company ProfileSoftTeco - Software Development Company Profile
SoftTeco - Software Development Company Profileakrivarotava
 
VictoriaMetrics Anomaly Detection Updates: Q1 2024
VictoriaMetrics Anomaly Detection Updates: Q1 2024VictoriaMetrics Anomaly Detection Updates: Q1 2024
VictoriaMetrics Anomaly Detection Updates: Q1 2024VictoriaMetrics
 
SensoDat: Simulation-based Sensor Dataset of Self-driving Cars
SensoDat: Simulation-based Sensor Dataset of Self-driving CarsSensoDat: Simulation-based Sensor Dataset of Self-driving Cars
SensoDat: Simulation-based Sensor Dataset of Self-driving CarsChristian Birchler
 
Exploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdf
Exploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdfExploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdf
Exploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdfkalichargn70th171
 
Strategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero resultsStrategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero resultsJean Silva
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtimeandrehoraa
 
eSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration toolseSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration toolsosttopstonverter
 
What’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 UpdatesWhat’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 UpdatesVictoriaMetrics
 
UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxUI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxAndreas Kunz
 
VK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web DevelopmentVK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web Developmentvyaparkranti
 
Osi security architecture in network.pptx
Osi security architecture in network.pptxOsi security architecture in network.pptx
Osi security architecture in network.pptxVinzoCenzo
 
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...OnePlan Solutions
 
2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shards2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shardsChristopher Curtin
 

Recently uploaded (20)

Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...Simplifying Microservices & Apps - The art of effortless development - Meetup...
Simplifying Microservices & Apps - The art of effortless development - Meetup...
 
Best Angular 17 Classroom & Online training - Naresh IT
Best Angular 17 Classroom & Online training - Naresh ITBest Angular 17 Classroom & Online training - Naresh IT
Best Angular 17 Classroom & Online training - Naresh IT
 
Large Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and RepairLarge Language Models for Test Case Evolution and Repair
Large Language Models for Test Case Evolution and Repair
 
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full RecordingOpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
OpenChain Education Work Group Monthly Meeting - 2024-04-10 - Full Recording
 
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
Catch the Wave: SAP Event-Driven and Data Streaming for the Intelligence Ente...
 
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
Tech Tuesday - Mastering Time Management Unlock the Power of OnePlan's Timesh...
 
How to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion ApplicationHow to submit a standout Adobe Champion Application
How to submit a standout Adobe Champion Application
 
SoftTeco - Software Development Company Profile
SoftTeco - Software Development Company ProfileSoftTeco - Software Development Company Profile
SoftTeco - Software Development Company Profile
 
VictoriaMetrics Anomaly Detection Updates: Q1 2024
VictoriaMetrics Anomaly Detection Updates: Q1 2024VictoriaMetrics Anomaly Detection Updates: Q1 2024
VictoriaMetrics Anomaly Detection Updates: Q1 2024
 
SensoDat: Simulation-based Sensor Dataset of Self-driving Cars
SensoDat: Simulation-based Sensor Dataset of Self-driving CarsSensoDat: Simulation-based Sensor Dataset of Self-driving Cars
SensoDat: Simulation-based Sensor Dataset of Self-driving Cars
 
Exploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdf
Exploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdfExploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdf
Exploring Selenium_Appium Frameworks for Seamless Integration with HeadSpin.pdf
 
Strategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero resultsStrategies for using alternative queries to mitigate zero results
Strategies for using alternative queries to mitigate zero results
 
SpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at RuntimeSpotFlow: Tracking Method Calls and States at Runtime
SpotFlow: Tracking Method Calls and States at Runtime
 
eSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration toolseSoftTools IMAP Backup Software and migration tools
eSoftTools IMAP Backup Software and migration tools
 
What’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 UpdatesWhat’s New in VictoriaMetrics: Q1 2024 Updates
What’s New in VictoriaMetrics: Q1 2024 Updates
 
UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptxUI5ers live - Custom Controls wrapping 3rd-party libs.pptx
UI5ers live - Custom Controls wrapping 3rd-party libs.pptx
 
VK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web DevelopmentVK Business Profile - provides IT solutions and Web Development
VK Business Profile - provides IT solutions and Web Development
 
Osi security architecture in network.pptx
Osi security architecture in network.pptxOsi security architecture in network.pptx
Osi security architecture in network.pptx
 
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
Revolutionizing the Digital Transformation Office - Leveraging OnePlan’s AI a...
 
2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shards2024 DevNexus Patterns for Resiliency: Shuffle shards
2024 DevNexus Patterns for Resiliency: Shuffle shards
 

GDPR From the Trenches - Real-world examples of how companies are approaching compliance.

  • 1. GDPR From the Trenches Real-world examples of how companies are approaching compliance Magnus Valmot Ardoq Simen Breen SANDS Per Franzén Telia Norge Ian Stendera Ardoq
  • 4. Seeking legal counsel to help you structure compliance projects and assess risk Simen Breen | Senior Lawyer | SANDS
  • 5. How to start working with the GDPR?  The nature of the GDPR  The GDPR is not sector specific and there is no threshold for the applicability  Work in a structured way from the beginning, and prioritize your efforts.  Before you get down to the details of the GDPR you  … need to know what you are doing with personal data  … need to know what to prioritize
  • 6. There is no easy way out  No one-size-fits-all strategy for GDPR compliance  GDPR does not impact all businesses the same way, and the starting position is different  Most checklists are either incomplete or so vague that they don’t really help.  First steps should be the same:  Establish a project team  A mapping of personal data processing activities  A mapping of compliance with existing requirements on personal data protection and mapping of existing policies, documentation etc.
  • 7. Establish a project team • A GDPR compliance project must have sufficient internal resources to succeed • Including the relevant people in your organization is key • The project team needs to have basic knowledge of GDPR and the reason for doing the mapping process • The project manager and the team must be given sufficient time and resources • The project team should be able to make decisions without time-consuming internal processes • External advice if necessary; legal and information security
  • 8. Mapping the processing of personal data • What types of personal data you process • What are the purposes of the processing • What are the legal bases for your processing activities • What is the source of the data • Where is the data and what systems are used • Who is responsible for the processing and the data systems • How many persons does the processing comprise • Use of data processors • Transfer of data out of the EU/EEA • Activities as data processor • How to document this?
  • 9. Mapping of your processing activities is necessary for deciding how to go forward • Knowing what processing of personal data the business does is necessary to fulfill the requirements in the GDPR • Being able to understand which requirements are relevant for your business • Being able to concretize the principles etc. to requirements • Being able to make instructions and procedures that actually work in practice
  • 10. Mapping of your processing activities is necessary for deciding how to go forward • To be able to make priorities (if necessary) • Priorities should not be made based on assessing the article in itself • Priorities should be made considering the processing activities and the risks related thereto • Which processing operations are high risk (to the rights and freedoms of natural persons or legal risk) or business critical
  • 11. Get it right from the start • You have to structure your compliance project based on your business ▪ Your data processing is the key ▪ Current compliance status is relevant – depending on jurisdiction • Even though the legal requirements are the same for everyone, their practical effects vary greatly • A risk-based approach
  • 12. Contact Simen Evensen Breen seb@sands.no +47 928 20 300 +47 22 81 46 24
  • 14. Experience from an ‟overwhelmed” project manager Per Franzén, Project Manager
  • 15. EXPERIENCE FROM A PROJECT MANAGER: OVERWHELMING AMOUNT OF GDPR TERMINOLOGY AND INSTRUCTIONS Data minimizationIndividual Rights Purpose limitation - Where do I start? - Are there any guidelines? - How does the GDPR terminology and instructions relate, or do they?
  • 16. “REACHING COMPLIANCE LEVEL ON GDPR IS KEY FOR OUR BUSINESS AND THEREFORE ONE OF OUR TOP PRIORITIES UNTIL JUNE 2018.” THIS IS THE GUIDANCE FROM TELIA CORPORATE MANAGEMENT GEM AMBITION
  • 17. Business Vision and Drivers - Privacy GDPR Requirements NO Legal Requirements NO Privacy Strategy Telia Company Information Asset & Vendor management –project, GSO/ITAT Processes, services /products and IT Asset and vendor management Telia Norge AS EA and IT Governance – GDPR NO Business Architecture Architecture Vision Information and System Architecture Technology Architecture Telia Norge ASTelia Norge GDPR Compliance project GDPR WORK STREAM (in Group Security & Privacy) Work stream management Employee privacy Awareness and com. IT and enterprise architecture Stakeholders DPO Norway PSG GDPR Norway Projects and activities Project Vega - Security NO IT EA Governance NO IT Architecture project Digital Telco initiative Development Trust as a Service System Dev Teams Line org Orderchange Project Management and business readiness Run Project and coordinate with Group Align with other Projects and activities in Norway Prepare business to operate new GDPR requirements Transition planning and execution Opportunities and solutions Migration planning Implementation Goverance Accountable (business) B2B Management B2C Management OneCall Management MyCall Management Chess Management HR Management Procurement Management Legal / Privacy Management Technology Management Security Management Privacy Policies and Objectives Input change (EPICs) - Observations Privacy Requirements Guidance Plans Architecture principles GSO Deliverables IN JANUARY 2017 I STARTED STRUCTURING THE PROJECT, AFTER WHICH WE SPENT 2 MONTHS ON THE AS-IS ANALYSIS, AND 1 MONTH ON GAP ANALYSIS  GDPRITProject
  • 18. AFTERWARDS I REALIZED THAT GDPR RIGHTS AND PRINCIPLES ARE BASED ON THE MANAGEMENT OF CUSTOMER AND EMPLOYEE PERSONAL DATA Resources OSS BSS Portal Employee Customer Portal GDPR Individual rights Authority CLI DataBase PrivacyData Goverance Data protection principles Telia Norge AS Partners Data Processors Employee Accountability
  • 19. BUSINESS ARCHITECTURE – HOW DOES GDPR RELATE TO TODAY’S OPERATIONS? Accountability Purposes Legal grounds CustomerEmployee Privacy Data - BO Business Process Roles Processes Systems OSS BSS Portal IT System Roles GDPR Individual rights functionality GDPR Data protection principles functionality Legal requirement TM Forum eTOM L3 Performance of contract Legitimate interests Individual’s consent IT System Roles in IdM GDPR Privacy Data Will be defined by GDPR Project Will be defined by GDPR Project Will be defined by GDPR Project Privacy by Design - Policies
  • 20. ACCOUNTABILITY IS CENTRAL – TARGET ARCHITECTURE QUALITY SYSTEM (NOW BUILT IN ARDOQ) Common Information Model Management Data (AS-IS) Accountability GDPR GDPR law Single consistent representation for all management data Management Data (TO-BE) Controls (Gap) Observations
  • 21. THE MODEL WE USE FOR WORKING IN ARDOQ AS-IS GDPR compliance TO-BE TO-BE TO-BE Observations
  • 22. OUR COMMON INFORMATION MODEL (CIM) IS CENTRAL (WORK IN PROGRESS)
  • 23. SOME EXAMPLE MODELS – EVERYTHING IS CONNECTED IN OUR CIM 
  • 24. HOW WE LINK THE REGULATION TO TELIA NORGE’S DAILY OPERATIONS
  • 25. WHY DO WE USE ARDOQ AND NOT EXCEL? 1. Value adding • When we first gather so much information, it should be useable across the organization • Our IT solution to provide automated GDR Individual rights and related GDPR Data protection principles are using Ardoq as a Policy/Rule engine 2. Maintenance – keeping information up-to-date continuously • Ardoq has support for automating via integrations (input and output) and simplifies manual documentation • We can automate Controls (Gaps) to verify compliance to GDPR (Observations) • GDPR Training for Personell will be using data from Ardoq – will be personalized 3. Traceability • We need to be able to trace how everything is connected and how they impact each other • We now have an AS-IS status of the relations between data elements in the CIM and can run predefined queries
  • 27. Lessons Learned Ian Stendera VP of Customer Development at Ardoq
  • 28. Lessons Learned • Compliance is continuous • Define realistic scope • Think structured
  • 34. Think Structured: handling attendees’ personal data Org Unit Personal Data Captured Sensitive Data? Processing Purpose Source Lawful Basis Systems handling personal data System Owner # of Data Subjects Transfered externally? Handled outside of EU? Marketing Name, Email, Telephone (optional), company No Manage Attendee Registration Eventbrite webform Consent Eventbrite, Prosperworks, Excel Marketing / Sales 50 Yes, systems are cloud SaaS solutions No Marketing Name, Email, Telephone (optional), company No Send Thank You and Presentations Eventbrite webform ? MailChimp Marketing 50 Yes, systems are cloud SaaS solutions No Marketing Name, Email, Telephone (optional), company No Register for Webinar Eventbrite webform Consent Eventbrite Marketing 50 Yes, systems are cloud SaaS solutions No
  • 35. Our mission: Transform compliance from a cost To a Value-adding process
  • 38. Thanks! Stick around for a Live Ardoq demo