How icims Supports. Your Readiness for the European Union General Data Protection Regulation

Similar documents
EU General Data Protection Regulation (GDPR) Achieving compliance

General Data Protection Regulation April 3, Sarah Ackerman, Managing Director Ross Patz, Consultant

THE GDPR PCLOUD'S ROAD TO FULL COMPLIANCE

Our agenda. The basics

EU Data Protection Triple Threat for May of 2018 What Inside Counsel Needs to Know

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) The impact of doing business in Asia

The GDPR Are you ready?

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

GDPR COMPLIANCE REPORT

Google Cloud & the General Data Protection Regulation (GDPR)

Plan a Pragmatic Approach to the new EU Data Privacy Regulation

Disruptive Technologies Legal and Regulatory Aspects. 16 May 2017 Investment Summit - Swiss Gobal Enterprise

Cybersecurity Considerations for GDPR

GDPR: A GUIDE TO READINESS

Accelerate GDPR compliance with the Microsoft Cloud

GDPR: A QUICK OVERVIEW

GDPR and the Privacy Shield

1. Right of access. Last Approval Date: May 2018

General Data Protection Regulation (GDPR) and the Implications for IT Service Management

THE NEW EU DATA PROTECTION REGULATION: WHAT IS IT AND WHAT DO WE NEED TO DO? KALLIOPI SPYRIDAKI CHIEF PRIVACY STRATEGIST, EUROPE

GDPR compliance: some basics & practical to do list

EU GDPR and . The complete text of the EU GDPR can be found at What is GDPR?

Protecting your data. EY s approach to data privacy and information security

Getting ready for GDPR. Philipp Hobler EMEA Field CTO Global Technology Office Dell EMC Data Protection Solutions

G DATA Whitepaper. The new EU General Data Protection Regulation - What businesses need to know

TRULY INDEPENDENT CYBER SECURITY SPECIALISTS. Cyber Major

PS Mailing Services Ltd Data Protection Policy May 2018

PRIVACY POLICY FOR WEB AND ONLINE TRADING PLATFORM

A Checklist for Cybersecurity and Data Privacy Diligence in TMT Transactions

Data Processing Clauses

IT MANAGEMENT AND THE GDPR: THE VMWARE PERSPECTIVE

Smart Software Licensing tools and Smart Account Management Privacy DataSheet

The Role of the Data Protection Officer

CNPD Course: Data Protection Basics

BHConsulting. Your trusted cybersecurity partner

EXAM PREPARATION GUIDE

PROJECT BACKGROUND AND RATIONALE

European Union Agency for Network and Information Security

Privacy Notice and Consent Form

GENERAL DATA PROTECTION REGULATION (GDPR)

PREPARING FOR THE GDPR AT THE UNIVERSITY OF HELSINKI

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe

Data Protection and GDPR

NOTICE OF PERSONAL DATA PROCESSING

SOLUTION BRIEF HELPING BREACH RESPONSE FOR GDPR WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE

EU GDPR & NEW YORK CYBERSECURITY REQUIREMENTS 3 KEYS TO SUCCESS

Cloud is the 'Only' Way Forward in Information Security. Leveraging Scale to Make the Unknown Known, in Dev, Sec & Ops.

EU DATA PRIVACY COMPLIANCE FOR US DRIVEN PROJECTS

WHITE PAPER. The General Data Protection Regulation: What Title It Means and How SAS Data Management Can Help

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary

SCCE ECEI 2014 EU DATA PRIVACY COMPLIANCE FOR US DRIVEN PROJECTS. Monica Salgado JANINE REGAN CIPP/E

On the Radar: IBM Resilient applies incident response orchestration to GDPR data breaches

Choosing the Right Solution for Strategic Deployment of Encryption

EY s data privacy service offering

Technology's role in General Data Protection Regulation Dr. Prokopios Drogkaris Officer in NIS SECPRE 2017 Oslo

Technical Requirements of the GDPR

Data Management and Security in the GDPR Era

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy.

How to Establish Security & Privacy Due Diligence in the Cloud

SHELTERMANAGER LTD CUSTOMER DATA PROCESSING AGREEMENT

What You Need to Know About Addressing GDPR Data Subject Rights in Pivot

GDPR - Are you ready?

WHITE PAPER. Meeting GDPR Challenges with Delphix. KuppingerCole Report

EU GDPR: The General Data Protection Regulation

Data Processing Agreement

FileFacets for GDPR. Solution Overview for Compliance. Copyright 2017 FileFacets Corporation. All rights reserved

PRIVACY NOTICE 1. Introduction

General Data Protection Regulation (GDPR) Key Facts & FAQ s

GDPR is here to stay. How prepared are you?

Managing Privacy Risk & Compliance in Financial Services. Brett Hamilton Advisory Solutions Consultant ServiceNow

Adtech and GDPR What to consider when choosing your partner

Swedish bank overcomes regulatory hurdles and embraces the cloud to foster innovation

Cisco Spark and GDPR. Thomas Flambeaux. Collaboration Consulting Solution Engineer, Security and Compliance. Cisco Connect 2018 Copenhagen April 12th

Privacy Notice For Ghana International Bank Plc customers

AWS Webinar. Navigating GDPR Compliance on AWS. Christian Hesse Amazon Web Services

GDPR Processor Security Controls. GDPR Toolkit Version 1 Datagator Ltd

Martijn Loderus. Merritt Maxim. Principal Analyst Forrester. Director & Global Practice Partner for Advisory Consulting Janrain

A practical guide to using ScheduleOnce in a GDPR compliant manner

EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations. For private circulation only.

GDPR: Get Prepared! A Checklist for Implementing a Security and Event Management Tool. Contact. Ashley House, Ashley Road London N17 9LZ

2. Which personal data is processed by SF Studios and from which source does the personal data originate?

General Data Protection Regulation (GDPR) FAQ

Eight Minute Expert GDPR

falanx Cyber ISO 27001: How and why your organisation should get certified

Arkadin Data protection & privacy white paper. Version May 2018

Magento GDPR Frequently Asked Questions

Forms. GDPR for Zoho Forms

Overview of Key E.U. and U.S. Privacy and Cybersecurity Laws. Brett Lockwood Smith, Gambrell & Russell, LLP May 15, 2018

ngenius Products in a GDPR Compliant Environment

Privacy Notice for Business Partners

BHConsulting. Your trusted cybersecurity partner

2. The Information we collect and how we use it: Individuals and Organisations: We collect and process personal data from individuals and organisation

A1 Complete Plumbing and Heating Limited Job Applicant Privacy Notice

Changing times in Swiss Data Privacy: new opportunities? Microsoft Security Day 27 April 2017 Clara-Ann Gordon

General Data Protection Regulation: Knowing your data. Title. Prepared by: Paul Barks, Managing Consultant

The GDPR data just got personal

Twilio cloud communications SECURITY

Transcription:

How icims Supports Your Readiness for the European Union General Data Protection Regulation The GDPR is the EU s next generation of data protection law. Aiming to strengthen the security and protection of personal data, the GDPR replaces the 1995 European Union Data Protection Directive. Companies like icims that value data security and privacy invest in being GDPR ready. Who is Impacted by the GDPR? The GDPR applies to organizations headquartered within the EU and organizations headquartered outside of the EU that offer goods or services to EU businesses. In our technology-driven world, this regulation impacts many global organizations.

What New Requirements Does the GDPR Have? The GDPR builds upon existing EU data protection law, but is different from the 1995 EU Privacy Directive that was based on fundamental principles and evolving guidance. GDPR takes a more extensive approach with 99 different articles and many sub articles. Regulations this comprehensive have never existed in the world of privacy before as these new regulations govern virtually every aspect of an organizations handling of personal data. The 99 Articles of the GDPR are as follows: General Provisions (1-4) Principles (5-11) Rights of the Data Subject (12 23) including: - Notice and consent to use data - Data access rights - Correction and rectification of data - Portability of data - Right to be forgotten Controller and Processor (24-43) Transfer of Personal Data to Third Countries or International Organizations (44-50) Independent Supervisory Authorities (51-59) Cooperation and Consistency (60-76) Remedies, Liability, and Penalties (77-84) Provisions Relating to Specific Processing Situations (85-91) Delegated Acts and Implementing Acts (92-93) Final Provisions (94-99) Some of the highlights within both new and enhanced requirements include: Direct regulation of data processors Data security obligations Data governance requirements, including policies, procedures and defined roles Requirements for data protection by design and default, and the conduct of data protection impact assessments Strict data breach notification timelines (generally 72 hours) A data protection officer for large scale processing of certain data Individual rights for data subjects, including: - Notice and consent to data use - Data access rights - Correction and rectification of data - Portability of data - Right to erasure of personal data The new regulation also comes with new penalties for non-compliance. Penalties can be triggered by one individual complaint and may be as high as four percent of global turnover or 20 million Euros (approx. $22.8 million USD), whichever is greater. Penalties may also include reprimands, bans, certification withdrawals or the imposition of a supervisory organization.

How is icims Prepared for the GDPR? icims is committed to complying with the GDPR and supporting its global customer base. This includes a company-wide initiative to ensure that icims satisfies internal GDPR requirements while also supporting its customers compliance. Processes & Policies icims has invested in information and data protection since its inception and its GDPR compliance plan was built on this solid foundation. Examples of compliance investments include: ISO Certification: According to the GDPR, approved certification methods may be used as an element to demonstrate compliance. icims annually tests and maintains an ISO/IEC 27001:2013 certification that broadly covers the production and operation environments for its talent platform. EU Privacy Shield: icims has completed the EU-U.S. Privacy Shield Certification by the U.S. Department of Commerce. Participation in the Privacy Shield program facilitates the transfer of personal data from the EU to the U.S. icims Information Security Policies: icims maintains detailed and comprehensive policies that apply to many of the areas covered by the GDPR including: Policies Included: Data Security and Privacy Policy Incident Response Policy and Procedure IT Security Policy Talent Platform Security Policy Comprehensive internal policies and process controls Areas Covered: Use of information Comprehensive information security Data handling Certified data centers Incident response Training and monitoring

Readiness Program Building off this strong foundation, icims had a comprehensive program across its entire operation to ensure that it was GDPR-ready. To address the complexity and risks of becoming GDPR-ready, icims used a multi-level approach that pools the knowledge of legal and regulatory counsel, consultants, and industry leaders while benchmarking its processes to globally accepted standards. Within the readiness program, icims developed a GDPR Compliance Framework which focuses on three groups: 1. Legal and Regulatory 2. Organizational 3. Technical Within these buckets, icims is covering key areas, including, but not limited to: Data Subject Rights Data Subject Consent Defining Roles and Responsibilities Embedding Privacy into and across all of the organizational and technical areas of the platform and corporate operations. As part of icims commitment to complying with the GDPR, icims team of experts have worked through a detailed remediation program. icims has completed analysis of every aspect of its company that touches personal data, including: The icims Talent Platform Corporate infrastructure Company processes icims systems

How Can My Organization Be GDPR Ready? icims understands that businesses today work with a variety of vendors. To ensure GDPR compliance, organizations should make sure their vendors have the know-how, experience and commitment to support the kinds of comprehensive measures that the GDPR requires. Data security and compliance are a top priority for icims as a best-of-breed recruitment technology provider. As icims existing data privacy and protection infrastructure demonstrates, icims has the history, skills, and commitment to continue to work diligently to create a secure, seamless user experience for icims customers in in the U.S., EU and around the world. icims is committed to maintaining GDPR compliance and enabling its customers to use the icims Talent Platform to assist in their own GDPR compliance. Visit gdpr-info.eu for more information on the GDPR and other EU data protection developments. About icims: icims is the leading provider of talent acquisition solutions that help businesses win the war for top talent. icims empowers companies to manage their entire hiring process within the industry s most robust Platformas-a-Service (PaaS). Built on the foundation of a best-to-market talent acquisition software suite, icims PaaS framework, UNIFi, allows employers to expand the capabilities of their core talent acquisition technology by integrating with the largest partner ecosystem in talent acquisition to help them attract, find, screen, and manage candidates. Offering scalable, easy-to-use solutions that are backed by award-winning customer service, icims supports more than 3,500 contracted customers and is one of the largest and fastest-growing talent acquisition solution providers.