SlideShare a Scribd company logo
1 of 41
Download to read offline
Wil Brown
@DeveloperWil
zeropointdevelopment.com for WordPress Sydney
Guidance on complying with the
new EU regulation
General Data Protection Regulation
Privacy law from European Commission protecting
rights of all EU citizens (28 member states) and
their personal data.
Approved April 2016.
Becomes effective May 25, 2018.
@DeveloperWil #wpsyd
Replaces 95/46/EC Directive of Data Protection
(1995) and is more extensive than 2011 Cookie
Law which is being replaced by EU ePrivacy
Regulation (EUePR/EUPR) soon after May 2018.
GDPR and EUPR will compliment each other.
Ref: GDPR Regulation and official PDF
@DeveloperWil #wpsyd
Probably the biggest shake up and most
important change in data privacy in the
last 20 years.
This is a BIG DEAL
@DeveloperWil #wpsyd
The EU GDPR is a law.
Use the information here as guidance.
Seek your own legal advice for modifying your
business operating policies and procedures.
@DeveloperWil #wpsyd
Facebook and Google already hit with $8.8 billion
in lawsuits on day one of GDPR.
“.. accusing the companies of coercing users into
sharing personal data.”
Ref: https://www.theverge.com/2018/5/25/17393766/facebook-
google-gdpr-lawsuit-max-schrems-europe
@DeveloperWil #wpsyd
Designed to protect the rights of EU citizens
Essentially impacts everyone with web access
unless you
– Actively block all 28 EU states IP addresses
Highly Impractical
– Actively track and block all EU citizens on the web
Highly Ilegal …unless you work for the NSA :-P
@DeveloperWil #wpsyd
“I am an Australian citizen with a WordPress
website – does GDPR affect me?”
Most likely yes it does.
1. If any EU citizen can interact with your website
2. Have establishment in the EU
3. Offer Goods and Services to EU
– EU language translation, offer shipping to an EU
state, using AdWords targeting EU audience
@DeveloperWil #wpsyd
• WP community site allowing users to create a
user profile (login); name, email, website
• An eCommerce (WooCommerce, EDD) store that
sells products; virtual = email, physical = address
• WP site that uses analytics software (Google
Analytics, Gtmetrix); IP address, cookies
• WP blog with newsletter subscription and
comments; name, email, IP address
• Firewall plugins; IP address (hacker unlikely to sue!)
@DeveloperWil #wpsyd
Data Controller
A business that controls personal data. If you have
collected and now possess personal data, and you
determine how that data is now dealt with
(including giving it to a 3rd party), you are likely
considered a controller under the regulations.
e.g. You, CRM systems, Facebook/Google
@DeveloperWil #wpsyd
Data Processor
A 3rd party company that you might give your data
to, who will use or manipulate your data in some
way.
e.g. Mailchimp, Campaign Monitor, Stripe, Paypal
@DeveloperWil #wpsyd
Consent
• Freely given: can I refuse/rescind my consent?
• Specific: what is my data being collected for?
• Informed: what are my rights?
• Unambiguous: how is my data being used?
• Statement or clear affirmative action
– Silence, pre-ticked checkbox or inaction does not
equal consent
@DeveloperWil #wpsyd
Establishment in the EU
Where you have any real and effective activity, no
matter if it is minimal or substantial, through a
stable arrangement in the EU, you are likely to be
‘established’ under the regulations.
e.g. permanent representation (a person), office.
@DeveloperWil #wpsyd
Processing
Any operation which is performed on personal
data, whether or not by automated means, such
as collection, recording, organisation, structuring,
storage, adaptation or alteration, retrieval,
consultation, use, disclosure by transmission,
dissemination or otherwise making available,
alignment or combination, restriction, erasure or
destruction;
@DeveloperWil #wpsyd
Data Protection Officer (DPO)
A data protection officer (DPO) is an enterprise
security leadership role required by the GDPR.
Data protection officers are responsible for
overseeing data protection strategy and
implementation to ensure compliance with GDPR.
@DeveloperWil #wpsyd
Applies to personal data (Art. 4)
Personally identifiable data (of a natural person –
think a Human Being), identified directly or
indirectly;
name, ID #, location, physical, psychological,
genetic, mental, economic, cultural or social
identity.
@DeveloperWil #wpsyd
Applies to any sensitive data (Art. 9)
Processing is prohibited for personal data
revealing racial or ethnic origin, political opinions,
religious or philosophical beliefs, trade union
membership, genetic data, biometric data, health
data, data concerning person’s sex life or sexual
orientation.
Exclusions apply; legal, medical, national security ..
@DeveloperWil #wpsyd
Requires that consent is given (Art. 7)
People must be given a true voluntary choice
whether or not they consent to give you their
data.
Need to add checkbox to all data collection forms
[✔]* I give consent to store and process my data
* = required
@DeveloperWil #wpsyd
Gives right to be forgotten (Art. 17)
Data controller must securely erase all personal
data they hold on requester without undue delay
When specific criteria are met – see Regulation.
– Data is no longer needed
– Purpose for collection has expired
– Data unlawfully processed …
@DeveloperWil #wpsyd
Privacy by design and default (Art. 25)
New “systems” collecting and processing data
must be inherently secure from concept.
You must build privacy and security into any new
apps, programs, websites, procedures etc.
@DeveloperWil #wpsyd
Gives right to know what info is being stored
You need to specify what data you will be
collecting and for what purposes up front and
before it has been collected.
Privacy Policy, Cookie Statement, T&C’s
@DeveloperWil #wpsyd
Gives right to access held info and data
portability (Art. 20)
You will need to provide all data held on requester
and supply that in a machine readable format for
importing into another system.
CSV, JSON, XSL file.
@DeveloperWil #wpsyd
• Notify authorities within 72 hours of data
breach and people whose data was accessed
• Data only used for reasons given at time of
collection and securely deleted after no longer
needed
• Parental consent required to process personal
data of children under 16 (Art. 8)
• Allows national authorities to impose fines on
companies breaching regulation
@DeveloperWil #wpsyd
If your business doesn’t comply with GPDR
• Get sanctioned up to 4% of the annual
worldwide turnover or fined up to €20 million
(the higher of the two), per infringement.
• Tiered approach to fines.
e.g. a company can be fined 2% for not having
their records in order, not notifying the
supervising authority and data subject about a
breach, or not conducting an impact
assessment. (Art. 83)
@DeveloperWil #wpsyd
Hire a good lawyer
A lawyer will provide you with tailored advice for
your business.
Ask friends and colleagues for recommendations
of lawyer contacts they have had a good
experience with.
Through Sydney Business Chambers
https://www.thechamber.com.au/
@DeveloperWil #wpsyd
Step 1
Review all data collection and processing
workflows
Work through entire WP site, document where
data is collected, processed and stored as well as
how long stored for:
– eCommerce check out page
– Payment gateways: Stripe/PayPal
– Email marketing: Mailchimp
– All forms on site: consent check box
– All generated cookies https://www.cookiebot.com/en/cookie-consent/
@DeveloperWil #wpsyd
Step 2
Update all legal documents
– Privacy Policy
– Terms & Conditions
– Cookie Statement
– Affiliate Terms
– NDA
– Project Contracts
– Contractor Agreements
@DeveloperWil #wpsyd
Step 3
Offer data portability
Ability to export all personal data in a transferrable
and importable document. e.g. csv, xml
Update to WordPress 4.9.6 to take advantage of
new data export feature.
@DeveloperWil #wpsyd
Step 4
Encrypt your data
1. Encrypt your transferred data (web traffic)
using HTTPS
Going HTTPS has other advantages too.
2. Encrypt your stored data
Not legally required to comply with GDPR but
highly recommended.
@DeveloperWil #wpsyd
Step 5
Self-Certify Under Privacy Shield Framework
Consider certifying under the EU-U.S. and Swiss-
U.S. Privacy Shield Frameworks if you are US
Established.
Provides companies on both sides of the Atlantic
with a mechanism to comply with data protection
requirements when transferring personal data
from the European Union and Switzerland to the
United States.
@DeveloperWil #wpsyd
Step 6
Check WP themes, plugins, services & APIs
• Contact Forms
– Gravity Forms, NinjaForms, WPForms
• Comment & Marketing Services
– Disqus, Jetpack, Mailchimp, Active Campaign, AWeber
• Analytics, Tracking & Remarketing
– Google Analytics, Hotjar, AdRoll
• eCommerce & Payment Processors
– WooCommerce, Easy Digital Downloads, Stripe, PayPal
• Community Plugins
– LearnDash, bbPress, BuddyPress
• All third-party APIs e.g. Is Google Fonts GDPR compliant?
@DeveloperWil #wpsyd
Step 7
v4.9.6 Privacy & Maintenance Release
– Logged out commenters given choice to store data in
a cookie
@DeveloperWil #wpsyd
v4.9.6 Privacy & Maintenance Release
– Privacy Policy Page
@DeveloperWil #wpsyd
v4.9.6 Privacy & Maintenance Release
– Data Export
@DeveloperWil #wpsyd
This plugin is meant to assist a Controller, Data
Processor, and Data Protection Officer (DPO) with
efforts to meet the obligations and rights enacted
under the GDPR.
GDPR https://wordpress.org/plugins/gdpr/
@DeveloperWil #wpsyd
With Stream, you’re never left in the dark about
WordPress Admin activity.
Every logged-in user action is displayed in an
activity stream and organized for easy filtering by
User, Role, Context, Action or IP address.
Stream https://en-au.wordpress.org/plugins/stream/
@DeveloperWil #wpsyd
WordPress’ most comprehensive real time user
activity and monitoring log plugin. It helps
thousands of WordPress administrators and
security professionals keep an eye on what is
happening on their websites.
WP Security Audit Log https://wordpress.org/plugins/wp-security-audit-log/
@DeveloperWil #wpsyd
http://eur-lex.europa.eu/legal-
content/EN/TXT/?qid=1517578296944&uri=CELEX%3A52018DC004
3
https://ec.europa.eu/commission/priorities/justice-and-
fundamental-rights/data-protection/2018-reform-eu-data-
protection-rules_en
https://kinsta.com/blog/gdpr-compliance/
https://codeable.io/gdpr-wordpress-woocommerce-starter-guide/
https://alphadigital.com.au/blog/gdpr-australian-retailers/
https://uploads-
ssl.webflow.com/596f08725f724769d8514755/5ad83ce924849422
c9707f76_Australian%20Privacy%20And%20Data.pdf
@DeveloperWil #wpsyd
[Front Cover] wordpress.org
[32] wordpress.org
[33] wordpress.org
[34] wordpress.org
[35] wordpress.org
[36] wordpress.org
[37] wordpress.org
[Back Cover] zeropointdevelopment.com
@DeveloperWil #wpsyd
▪ 20+ years in IT: Dev & SysOps
▪ WordPress Developer since 2008
▪ Plugins, APIs, Security & Systems Integrations
▪ Organiser WPSyd & WordCamp Sydney
zeropointdevelopment.com
@DeveloperWil
♥ Pizza & Craft Beer
@DeveloperWil #wpsyd
@DeveloperWil #wpsyd
@DeveloperWil

More Related Content

What's hot

GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
IoT - Attacks and Solutions
IoT - Attacks and SolutionsIoT - Attacks and Solutions
IoT - Attacks and SolutionsUlf Mattsson
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideZymplify
 
The European Union’s 
General Data Protection Regulation
The European Union’s 
General Data Protection Regulation The European Union’s 
General Data Protection Regulation
The European Union’s 
General Data Protection Regulation David Sayce
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckKyle Davies
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliantSiddharth Ram Dinesh
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in BerlinMailjet
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeIBB Law
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowPiwik PRO
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Lauren Isaacs
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)Madhumita Mantri
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Ulf Mattsson
 

What's hot (20)

GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
IoT - Attacks and Solutions
IoT - Attacks and SolutionsIoT - Attacks and Solutions
IoT - Attacks and Solutions
 
Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
Ensuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify GuideEnsuring GDPR Compliance - A Zymplify Guide
Ensuring GDPR Compliance - A Zymplify Guide
 
The European Union’s 
General Data Protection Regulation
The European Union’s 
General Data Protection Regulation The European Union’s 
General Data Protection Regulation
The European Union’s 
General Data Protection Regulation
 
VMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide DeckVMTN6642E - GDPR Slide Deck
VMTN6642E - GDPR Slide Deck
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliant
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
"GDPR - All You Need To Know" presentation from event Nov 16th in Berlin
 
Charity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of ChangeCharity Law Updates for 2018: Making the Most of Change
Charity Law Updates for 2018: Making the Most of Change
 
GDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to KnowGDPR Data Subject Rights - What You Need to Know
GDPR Data Subject Rights - What You Need to Know
 
Gdpr in a nutshell
Gdpr in a nutshellGdpr in a nutshell
Gdpr in a nutshell
 
Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?Cobb Digital Bitesize workshop - GDPR, are you compliant?
Cobb Digital Bitesize workshop - GDPR, are you compliant?
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)An Overview Of GDPR (General Data Protection Regulation)
An Overview Of GDPR (General Data Protection Regulation)
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...Evolving international privacy regulations and cross border data transfer - g...
Evolving international privacy regulations and cross border data transfer - g...
 

Similar to GDPR - General Data Protection Regulation

Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
GDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarGDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarSagittarius
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRCase IQ
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesOgilvy Consulting
 
GDPR, WordPress and You.
GDPR, WordPress and You.GDPR, WordPress and You.
GDPR, WordPress and You.WordCamp Sydney
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceObservePoint
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidencePrecisely
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR ComplianceAndreas Batsis
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxRahulGarg294918
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationcaniceconsulting
 
What Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRWhat Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRCrawfordGroup
 

Similar to GDPR - General Data Protection Regulation (20)

Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
GDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It WebinarGDPR Is Coming - Get Over It Webinar
GDPR Is Coming - Get Over It Webinar
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
GDPR, WordPress and You.
GDPR, WordPress and You.GDPR, WordPress and You.
GDPR, WordPress and You.
 
GPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-RightGPDR_Get-Data-Protection-Right
GPDR_Get-Data-Protection-Right
 
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in ComplianceThe GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
The GDPR Most Wanted: The Marketer and Analyst's Role in Compliance
 
Ritz 4th-july-gdpr
Ritz 4th-july-gdprRitz 4th-july-gdpr
Ritz 4th-july-gdpr
 
GDPR 101
GDPR 101GDPR 101
GDPR 101
 
Data Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with ConfidenceData Quality-Driven GDPR: Compliance with Confidence
Data Quality-Driven GDPR: Compliance with Confidence
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance9 Practical Steps 2 GDPR Compliance
9 Practical Steps 2 GDPR Compliance
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
 
Smart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislationSmart Data Module 5 d drive_legislation
Smart Data Module 5 d drive_legislation
 
ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR ZyLAB ACEDS Webinar- GDPR
ZyLAB ACEDS Webinar- GDPR
 
GDPR Part 1: Quick Facts
GDPR Part 1: Quick FactsGDPR Part 1: Quick Facts
GDPR Part 1: Quick Facts
 
What Marketers Need To Know About GDPR
What Marketers Need To Know About GDPRWhat Marketers Need To Know About GDPR
What Marketers Need To Know About GDPR
 

Recently uploaded

Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Sonam Pathan
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa494f574xmv
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Paul Calvano
 
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一Fs
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书zdzoqco
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Dana Luther
 
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作ys8omjxb
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012rehmti665
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一z xss
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationLinaWolf1
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一Fs
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一Fs
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhimiss dipika
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Excelmac1
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Sonam Pathan
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITMgdsc13
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMartaLoveguard
 

Recently uploaded (20)

Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24
 
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
 
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 Documentation
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhi
 
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITM
 
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
 
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Serviceyoung call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptx
 

GDPR - General Data Protection Regulation

  • 1. Wil Brown @DeveloperWil zeropointdevelopment.com for WordPress Sydney Guidance on complying with the new EU regulation
  • 2. General Data Protection Regulation Privacy law from European Commission protecting rights of all EU citizens (28 member states) and their personal data. Approved April 2016. Becomes effective May 25, 2018. @DeveloperWil #wpsyd
  • 3. Replaces 95/46/EC Directive of Data Protection (1995) and is more extensive than 2011 Cookie Law which is being replaced by EU ePrivacy Regulation (EUePR/EUPR) soon after May 2018. GDPR and EUPR will compliment each other. Ref: GDPR Regulation and official PDF @DeveloperWil #wpsyd
  • 4. Probably the biggest shake up and most important change in data privacy in the last 20 years. This is a BIG DEAL @DeveloperWil #wpsyd
  • 5. The EU GDPR is a law. Use the information here as guidance. Seek your own legal advice for modifying your business operating policies and procedures. @DeveloperWil #wpsyd
  • 6. Facebook and Google already hit with $8.8 billion in lawsuits on day one of GDPR. “.. accusing the companies of coercing users into sharing personal data.” Ref: https://www.theverge.com/2018/5/25/17393766/facebook- google-gdpr-lawsuit-max-schrems-europe @DeveloperWil #wpsyd
  • 7. Designed to protect the rights of EU citizens Essentially impacts everyone with web access unless you – Actively block all 28 EU states IP addresses Highly Impractical – Actively track and block all EU citizens on the web Highly Ilegal …unless you work for the NSA :-P @DeveloperWil #wpsyd
  • 8. “I am an Australian citizen with a WordPress website – does GDPR affect me?” Most likely yes it does. 1. If any EU citizen can interact with your website 2. Have establishment in the EU 3. Offer Goods and Services to EU – EU language translation, offer shipping to an EU state, using AdWords targeting EU audience @DeveloperWil #wpsyd
  • 9. • WP community site allowing users to create a user profile (login); name, email, website • An eCommerce (WooCommerce, EDD) store that sells products; virtual = email, physical = address • WP site that uses analytics software (Google Analytics, Gtmetrix); IP address, cookies • WP blog with newsletter subscription and comments; name, email, IP address • Firewall plugins; IP address (hacker unlikely to sue!) @DeveloperWil #wpsyd
  • 10. Data Controller A business that controls personal data. If you have collected and now possess personal data, and you determine how that data is now dealt with (including giving it to a 3rd party), you are likely considered a controller under the regulations. e.g. You, CRM systems, Facebook/Google @DeveloperWil #wpsyd
  • 11. Data Processor A 3rd party company that you might give your data to, who will use or manipulate your data in some way. e.g. Mailchimp, Campaign Monitor, Stripe, Paypal @DeveloperWil #wpsyd
  • 12. Consent • Freely given: can I refuse/rescind my consent? • Specific: what is my data being collected for? • Informed: what are my rights? • Unambiguous: how is my data being used? • Statement or clear affirmative action – Silence, pre-ticked checkbox or inaction does not equal consent @DeveloperWil #wpsyd
  • 13. Establishment in the EU Where you have any real and effective activity, no matter if it is minimal or substantial, through a stable arrangement in the EU, you are likely to be ‘established’ under the regulations. e.g. permanent representation (a person), office. @DeveloperWil #wpsyd
  • 14. Processing Any operation which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; @DeveloperWil #wpsyd
  • 15. Data Protection Officer (DPO) A data protection officer (DPO) is an enterprise security leadership role required by the GDPR. Data protection officers are responsible for overseeing data protection strategy and implementation to ensure compliance with GDPR. @DeveloperWil #wpsyd
  • 16. Applies to personal data (Art. 4) Personally identifiable data (of a natural person – think a Human Being), identified directly or indirectly; name, ID #, location, physical, psychological, genetic, mental, economic, cultural or social identity. @DeveloperWil #wpsyd
  • 17. Applies to any sensitive data (Art. 9) Processing is prohibited for personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning person’s sex life or sexual orientation. Exclusions apply; legal, medical, national security .. @DeveloperWil #wpsyd
  • 18. Requires that consent is given (Art. 7) People must be given a true voluntary choice whether or not they consent to give you their data. Need to add checkbox to all data collection forms [✔]* I give consent to store and process my data * = required @DeveloperWil #wpsyd
  • 19. Gives right to be forgotten (Art. 17) Data controller must securely erase all personal data they hold on requester without undue delay When specific criteria are met – see Regulation. – Data is no longer needed – Purpose for collection has expired – Data unlawfully processed … @DeveloperWil #wpsyd
  • 20. Privacy by design and default (Art. 25) New “systems” collecting and processing data must be inherently secure from concept. You must build privacy and security into any new apps, programs, websites, procedures etc. @DeveloperWil #wpsyd
  • 21. Gives right to know what info is being stored You need to specify what data you will be collecting and for what purposes up front and before it has been collected. Privacy Policy, Cookie Statement, T&C’s @DeveloperWil #wpsyd
  • 22. Gives right to access held info and data portability (Art. 20) You will need to provide all data held on requester and supply that in a machine readable format for importing into another system. CSV, JSON, XSL file. @DeveloperWil #wpsyd
  • 23. • Notify authorities within 72 hours of data breach and people whose data was accessed • Data only used for reasons given at time of collection and securely deleted after no longer needed • Parental consent required to process personal data of children under 16 (Art. 8) • Allows national authorities to impose fines on companies breaching regulation @DeveloperWil #wpsyd
  • 24. If your business doesn’t comply with GPDR • Get sanctioned up to 4% of the annual worldwide turnover or fined up to €20 million (the higher of the two), per infringement. • Tiered approach to fines. e.g. a company can be fined 2% for not having their records in order, not notifying the supervising authority and data subject about a breach, or not conducting an impact assessment. (Art. 83) @DeveloperWil #wpsyd
  • 25. Hire a good lawyer A lawyer will provide you with tailored advice for your business. Ask friends and colleagues for recommendations of lawyer contacts they have had a good experience with. Through Sydney Business Chambers https://www.thechamber.com.au/ @DeveloperWil #wpsyd Step 1
  • 26. Review all data collection and processing workflows Work through entire WP site, document where data is collected, processed and stored as well as how long stored for: – eCommerce check out page – Payment gateways: Stripe/PayPal – Email marketing: Mailchimp – All forms on site: consent check box – All generated cookies https://www.cookiebot.com/en/cookie-consent/ @DeveloperWil #wpsyd Step 2
  • 27. Update all legal documents – Privacy Policy – Terms & Conditions – Cookie Statement – Affiliate Terms – NDA – Project Contracts – Contractor Agreements @DeveloperWil #wpsyd Step 3
  • 28. Offer data portability Ability to export all personal data in a transferrable and importable document. e.g. csv, xml Update to WordPress 4.9.6 to take advantage of new data export feature. @DeveloperWil #wpsyd Step 4
  • 29. Encrypt your data 1. Encrypt your transferred data (web traffic) using HTTPS Going HTTPS has other advantages too. 2. Encrypt your stored data Not legally required to comply with GDPR but highly recommended. @DeveloperWil #wpsyd Step 5
  • 30. Self-Certify Under Privacy Shield Framework Consider certifying under the EU-U.S. and Swiss- U.S. Privacy Shield Frameworks if you are US Established. Provides companies on both sides of the Atlantic with a mechanism to comply with data protection requirements when transferring personal data from the European Union and Switzerland to the United States. @DeveloperWil #wpsyd Step 6
  • 31. Check WP themes, plugins, services & APIs • Contact Forms – Gravity Forms, NinjaForms, WPForms • Comment & Marketing Services – Disqus, Jetpack, Mailchimp, Active Campaign, AWeber • Analytics, Tracking & Remarketing – Google Analytics, Hotjar, AdRoll • eCommerce & Payment Processors – WooCommerce, Easy Digital Downloads, Stripe, PayPal • Community Plugins – LearnDash, bbPress, BuddyPress • All third-party APIs e.g. Is Google Fonts GDPR compliant? @DeveloperWil #wpsyd Step 7
  • 32. v4.9.6 Privacy & Maintenance Release – Logged out commenters given choice to store data in a cookie @DeveloperWil #wpsyd
  • 33. v4.9.6 Privacy & Maintenance Release – Privacy Policy Page @DeveloperWil #wpsyd
  • 34. v4.9.6 Privacy & Maintenance Release – Data Export @DeveloperWil #wpsyd
  • 35. This plugin is meant to assist a Controller, Data Processor, and Data Protection Officer (DPO) with efforts to meet the obligations and rights enacted under the GDPR. GDPR https://wordpress.org/plugins/gdpr/ @DeveloperWil #wpsyd
  • 36. With Stream, you’re never left in the dark about WordPress Admin activity. Every logged-in user action is displayed in an activity stream and organized for easy filtering by User, Role, Context, Action or IP address. Stream https://en-au.wordpress.org/plugins/stream/ @DeveloperWil #wpsyd
  • 37. WordPress’ most comprehensive real time user activity and monitoring log plugin. It helps thousands of WordPress administrators and security professionals keep an eye on what is happening on their websites. WP Security Audit Log https://wordpress.org/plugins/wp-security-audit-log/ @DeveloperWil #wpsyd
  • 39. [Front Cover] wordpress.org [32] wordpress.org [33] wordpress.org [34] wordpress.org [35] wordpress.org [36] wordpress.org [37] wordpress.org [Back Cover] zeropointdevelopment.com @DeveloperWil #wpsyd
  • 40. ▪ 20+ years in IT: Dev & SysOps ▪ WordPress Developer since 2008 ▪ Plugins, APIs, Security & Systems Integrations ▪ Organiser WPSyd & WordCamp Sydney zeropointdevelopment.com @DeveloperWil ♥ Pizza & Craft Beer @DeveloperWil #wpsyd