SlideShare a Scribd company logo
1 of 11
General Data Protection 
Regulation, 2014 
Update document 
David Prince, CISSP, CISM 
Director – Information Security Consulting, Schillings 
@RiskObscurity 
InfoRisk.io
About me… 
①Information security evangelist 
②On-demand CISO/vCISO 
③Industry speaker and socialite 
①Director of Information Security Consulting @ Schillings 
②Blogger – InfoRisk.io/Schillings.co.uk 
③Give01Day Supporter! 
④ f
What is the General Data 
Protection Regulation? 
The purpose of the General Data Protection Regulation (“GDPR”) is to replace 
existing and incredibly outdated Data Protection legislation in-acted by various 
EU member-states with a single, unified regulation for protecting Personal Data. 
The Draft GDPR was introduced by the European Commission (“EC”) in January 
2012 with the latest version of the draft approved by the European Parliament in 
March 2014. 
Given the fundamental change in Data Protection at EU-level, there is still much 
negotiation to take place and it is suspected that the final form will not be 
approved until late next year, with a further 2-year enforcement deadline. 
However, with over 4,000 proposed amendments to the original legislation 
organizations should be reviewing their current Data Protection and Information 
Security posture now in preparation for this significant regulatory change. 
This slide-deck will outline just some of the most substantial changes organizations 
need to be aware of. 
① f
Increased fines 
Currently, under the Data Protection Act in the UK, the maximum penalty for 
non-compliance is £500,000, although the ICO (Information Commissioners 
Office), the UK Authority for the Data Protection Act, has only issued a maximum 
fine of £250,000. 
Many believe that these thresholds are far to low, given the devastation a loss of 
data can cause and its potential to cause even greater harm as we adopt 
Cloud computing and the Internet of Things (“IoT”) 
The new General Data Protection Regulation will come with fines of up to 5% of 
annual group-wide revenue, or €100 million, whichever sum is greatest. 
This is a substantial change that all organizations should take on board when 
allocating budget and priority to Data Protection and Information Security 
① f
Notification requirements 
According to the latest draft of the GDPR, organizations will be required to notify 
the National Supervisory Authority of all data breaches without undue delay 
within 72 hours, in addition to notifying the affected individuals of data-loss, 
similar to certain US federal law on Data Protection. E.g. the state of California. 
In instances were data has been encrypted and is unreadable (and therefore 
not compromised in terms of its Confidentiality and Integrity) it may not be 
necessary to notify. 
Currently, one of the biggest reasons for organizations being fine is due to lost or 
stolen devices that do not employ encryption. 
This requirement to notify means that organizations can no longer brush data-loss 
incidents under the rug and increases the likelihood of significant reputation 
and financial harm in the event of data loss.
Data Privacy Impact 
Assessments (DPIA) 
Both Data Controllers and Data Processors will be required to perform Data 
Privacy Impact Assessments (DPIAs) to identify how data handling procedures 
and processes (including what Personal Data is used for) could impact the 
safety of information associated to data-subjects, and overall compliance of 
that information under the GDPR 
This change will put in place greater administrative overhead to ensure 
compliance. Additionally, this change enforces Data Processors to become 
more responsible in ensuring Data Protection by mandating their compliance 
with the GDPR. 
This change aims to minimize Data Protection risk in the supply chain, which is 
often a cause of vulnerability that results in data-losses, which the Data 
Controller is accountable for.
Mandatory appointment of 
Data Protection Officer (DPO) 
Organizations that process the personal information of 5,000 individuals or more 
annually, or maintain data processing as a core business function will be 
required to hire a Data Protection Officer (DPO) to oversee data processing 
operations. 
Importantly, to ensure severance from business politics and conflicts of interest, 
this individual will be given enhanced employment rights, including a minimum 
tenure of 4 years, full time and 2 years for a contractor. 
Organizations may hire a single DPO for the entire business. However, they must, 
in all cases, have knowledge and experience in Data Protection law. 
Public authorities will be required to appoint a DPO regardless of the number of 
individuals’ personal data they process.
Application to non-EU 
organizations 
Organizations that are not based within the EU, but target EU citizens with goods 
and services will be required to comply with the GDPR.
Application to Data Processors 
In the current Data Protection Act, Data Controllers are entirely accountable for 
the protection of Personal Data, even if some of that data is processed by third-party 
organizations acting as Data Processors. 
Under the GDPR Data Processors will be required to comply with the GDPR 
which means they share the liability of data-loss incidents and non-compliance.
Application to Data Processors 
In the current Data Protection Act, Data Controllers are entirely accountable for 
the protection of Personal Data, even if some of that data is processed by third-party 
organizations acting as Data Processors. 
Under the GDPR Data Processors will be required to comply with the GDPR 
which means they share the liability of data-loss incidents and non-compliance.
Thank you. 
Other changes to be aware of: 
1. Right to be forgotten. 
Click here to see Select Committee report in July 2014. 
1. Explicit Consent. 
Individuals are required to give consent for their data 
to be processed. 
David Prince, CISSP, CISM 
Director – Information Security Consulting, Schillings 
@RiskObscurity 
InfoRisk.io

More Related Content

Recently uploaded

INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxnyabatejosphat1
 
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdflaysamaeguardiano
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsAurora Consulting
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptxPamelaAbegailMonsant2
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxMollyBrown86
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxRRR Chambers
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionAnuragMishra811030
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubham Wadhonkar
 
Chp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptChp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptzainabbkhaleeq123
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhaiShashankKumar441258
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxRRR Chambers
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm2020000445musaib
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxRRR Chambers
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881mayurchatre90
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxRRR Chambers
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULEsreeramsaipranitha
 

Recently uploaded (20)

INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptx
 
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusion
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptx
 
Chp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptChp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .ppt
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
 
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
 

Featured

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

Featured (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

General Data Protection Regulation - 2014 Updates

  • 1. General Data Protection Regulation, 2014 Update document David Prince, CISSP, CISM Director – Information Security Consulting, Schillings @RiskObscurity InfoRisk.io
  • 2. About me… ①Information security evangelist ②On-demand CISO/vCISO ③Industry speaker and socialite ①Director of Information Security Consulting @ Schillings ②Blogger – InfoRisk.io/Schillings.co.uk ③Give01Day Supporter! ④ f
  • 3. What is the General Data Protection Regulation? The purpose of the General Data Protection Regulation (“GDPR”) is to replace existing and incredibly outdated Data Protection legislation in-acted by various EU member-states with a single, unified regulation for protecting Personal Data. The Draft GDPR was introduced by the European Commission (“EC”) in January 2012 with the latest version of the draft approved by the European Parliament in March 2014. Given the fundamental change in Data Protection at EU-level, there is still much negotiation to take place and it is suspected that the final form will not be approved until late next year, with a further 2-year enforcement deadline. However, with over 4,000 proposed amendments to the original legislation organizations should be reviewing their current Data Protection and Information Security posture now in preparation for this significant regulatory change. This slide-deck will outline just some of the most substantial changes organizations need to be aware of. ① f
  • 4. Increased fines Currently, under the Data Protection Act in the UK, the maximum penalty for non-compliance is £500,000, although the ICO (Information Commissioners Office), the UK Authority for the Data Protection Act, has only issued a maximum fine of £250,000. Many believe that these thresholds are far to low, given the devastation a loss of data can cause and its potential to cause even greater harm as we adopt Cloud computing and the Internet of Things (“IoT”) The new General Data Protection Regulation will come with fines of up to 5% of annual group-wide revenue, or €100 million, whichever sum is greatest. This is a substantial change that all organizations should take on board when allocating budget and priority to Data Protection and Information Security ① f
  • 5. Notification requirements According to the latest draft of the GDPR, organizations will be required to notify the National Supervisory Authority of all data breaches without undue delay within 72 hours, in addition to notifying the affected individuals of data-loss, similar to certain US federal law on Data Protection. E.g. the state of California. In instances were data has been encrypted and is unreadable (and therefore not compromised in terms of its Confidentiality and Integrity) it may not be necessary to notify. Currently, one of the biggest reasons for organizations being fine is due to lost or stolen devices that do not employ encryption. This requirement to notify means that organizations can no longer brush data-loss incidents under the rug and increases the likelihood of significant reputation and financial harm in the event of data loss.
  • 6. Data Privacy Impact Assessments (DPIA) Both Data Controllers and Data Processors will be required to perform Data Privacy Impact Assessments (DPIAs) to identify how data handling procedures and processes (including what Personal Data is used for) could impact the safety of information associated to data-subjects, and overall compliance of that information under the GDPR This change will put in place greater administrative overhead to ensure compliance. Additionally, this change enforces Data Processors to become more responsible in ensuring Data Protection by mandating their compliance with the GDPR. This change aims to minimize Data Protection risk in the supply chain, which is often a cause of vulnerability that results in data-losses, which the Data Controller is accountable for.
  • 7. Mandatory appointment of Data Protection Officer (DPO) Organizations that process the personal information of 5,000 individuals or more annually, or maintain data processing as a core business function will be required to hire a Data Protection Officer (DPO) to oversee data processing operations. Importantly, to ensure severance from business politics and conflicts of interest, this individual will be given enhanced employment rights, including a minimum tenure of 4 years, full time and 2 years for a contractor. Organizations may hire a single DPO for the entire business. However, they must, in all cases, have knowledge and experience in Data Protection law. Public authorities will be required to appoint a DPO regardless of the number of individuals’ personal data they process.
  • 8. Application to non-EU organizations Organizations that are not based within the EU, but target EU citizens with goods and services will be required to comply with the GDPR.
  • 9. Application to Data Processors In the current Data Protection Act, Data Controllers are entirely accountable for the protection of Personal Data, even if some of that data is processed by third-party organizations acting as Data Processors. Under the GDPR Data Processors will be required to comply with the GDPR which means they share the liability of data-loss incidents and non-compliance.
  • 10. Application to Data Processors In the current Data Protection Act, Data Controllers are entirely accountable for the protection of Personal Data, even if some of that data is processed by third-party organizations acting as Data Processors. Under the GDPR Data Processors will be required to comply with the GDPR which means they share the liability of data-loss incidents and non-compliance.
  • 11. Thank you. Other changes to be aware of: 1. Right to be forgotten. Click here to see Select Committee report in July 2014. 1. Explicit Consent. Individuals are required to give consent for their data to be processed. David Prince, CISSP, CISM Director – Information Security Consulting, Schillings @RiskObscurity InfoRisk.io