General Data Protection Regulation April 3, Sarah Ackerman, Managing Director Ross Patz, Consultant

Similar documents
EU General Data Protection Regulation (GDPR) Achieving compliance

General Data Protection Regulation (GDPR)

Emsi Privacy Shield Policy

Privacy Shield Policy

How icims Supports. Your Readiness for the European Union General Data Protection Regulation

Islam21c.com Data Protection and Privacy Policy

Overview of Key E.U. and U.S. Privacy and Cybersecurity Laws. Brett Lockwood Smith, Gambrell & Russell, LLP May 15, 2018

Plan a Pragmatic Approach to the new EU Data Privacy Regulation

PRIVACY COMMITMENT. Information We Collect and How We Use It. Effective Date: July 2, 2018

VERSION 1.3 MAY 1, 2018 SNOWFLY PRIVACY POLICY SNOWFLY PERFORMANCE INC. P.O. BOX 95254, SOUTH JORDAN, UT

GETTING PRIVACY SHIELD RIGHT

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

CNH Industrial Privacy Policy. This Privacy Policy relates to our use of any personal information you provide to us.

VIACOM INC. PRIVACY SHIELD PRIVACY POLICY

EU-US PRIVACY SHIELD POLICY (Updated April 11, 2018)

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy.

General Data Protection Regulation (GDPR) The impact of doing business in Asia

PS Mailing Services Ltd Data Protection Policy May 2018

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2

CEM Benchmarking Privacy Policy

Google Cloud & the General Data Protection Regulation (GDPR)

The Role of the Data Protection Officer

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal

GDPR - Are you ready?

Privacy Policy. Effective as of October 5, 2017

GDPR and the Privacy Shield

Vistra International Expansion Limited PRIVACY NOTICE

Magento GDPR Frequently Asked Questions

General Data Protection Regulation (GDPR) NEW RULES

GDPR compliance: some basics & practical to do list

Cisco Spark and GDPR. Thomas Flambeaux. Collaboration Consulting Solution Engineer, Security and Compliance. Cisco Connect 2018 Copenhagen April 12th

BHBIA New Data Protection Rules. Pharma Company Perspective. Guy Murray Director, Market Research & Analytics, GC&BI MR Operations and Compliance, MSD

Data Protection Policy

Saba Hosted Customer Privacy Policy

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

HPE DATA PRIVACY AND SECURITY

Five Ways that Privacy Shield is Different from Safe Harbor and Five Simple Steps Companies Can Take to Prepare for Certification

Privacy Statement for Use of the Certification Service of Swisscom (sales name: "All-in Signing Service")

Conjure Network LLC Privacy Policy

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

Privacy Shield Boot Camp 2016

OUR PRIVACY POLICY. 1. Our Privacy Principles. 2. Information that We Collect from You. Last Updated: May 25, 2018

VISTRA ZURICH AG - PRIVACY NOTICE

CTI BioPharma Privacy Notice

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to

Disruptive Technologies Legal and Regulatory Aspects. 16 May 2017 Investment Summit - Swiss Gobal Enterprise

1. How we process Personal Data from and about you.

Data Processing Clauses

GDPR: A QUICK OVERVIEW

Data Privacy & Protection in the EU-U.S.

PRIVACY POLICY FOR WEB AND ONLINE TRADING PLATFORM

City, University of London Institutional Repository. This version of the publication may differ from the final published version.

Secure Messaging Mobile App Privacy Policy. Privacy Policy Highlights

Changing times in Swiss Data Privacy: new opportunities? Microsoft Security Day 27 April 2017 Clara-Ann Gordon

Cybersecurity Considerations for GDPR

Data Protection in Switzerland Update Following the Safe Harbor Decision. 21 October 2015 / 6 February 2016 Christian Wyss

Smart Software Licensing tools and Smart Account Management Privacy DataSheet

DATA PROCESSING TERMS

1. Right of access. Last Approval Date: May 2018

PRIVACY POLICY Last Updated May, 2018

GDPR AMC SAAS AND HOSTED MODULES. UK version. AMC Consult A/S June 26, 2018 Version 1.10

DATA PROCESSING AGREEMENT

VISTRA (CYPRUS) LTD. PRIVACY NOTICE

PRIVACY POLICY. We encourage you to read the entire Privacy Policy, which consists of the sections listed below:

PRIVACY STATEMENT +41 (0) Rue du Rhone , Martigny, Switzerland.

Motorola Mobility Binding Corporate Rules (BCRs)

Q&A for Citco Fund Services clients The General Data Protection Regulation ( GDPR )

Privacy Policy Effective May 25 th 2018

Catalent Inc. Privacy Policy v.1 Effective Date: May 25, 2018 Page 1

GUESTBOOK REWARDS, INC. Privacy Policy

EU GDPR & ISO Integrated Documentation Toolkit integrated-documentation-toolkit

Recruitment Privacy Notice

Accelerate GDPR compliance with the Microsoft Cloud

SHELTERMANAGER LTD CUSTOMER DATA PROCESSING AGREEMENT

BIOEVENTS PRIVACY POLICY

Managing Privacy Risk & Compliance in Financial Services. Brett Hamilton Advisory Solutions Consultant ServiceNow

Thanks for using Dropbox! Here we describe how we collect, use and handle your information when

Data Protection Policy

Workday s Robust Privacy Program

General Data Protection Regulation (GDPR) Key Facts & FAQ s

DATA PROTECTION BY DESIGN

PRIVACY NOTICE STORM RECRUITMENT UNIT 11, 2 ND FLOOR CHARLESLAND CENTRE, GREYSTONES, CO. WICKLOW 1. INTRODUCTION

G DATA Whitepaper. The new EU General Data Protection Regulation - What businesses need to know

Spring Mobile Mini UK Ltd. Privacy Policy Spring 2018

VISTRA MONACO PRIVACY NOTICE

Proposal for a model to address the General Data Protection Regulation (GDPR)

GDPR Compliant. Privacy Policy. Updated 24/05/2018

EU GDPR: The General Data Protection Regulation

Arkadin Data protection & privacy white paper. Version May 2018

Privacy Policy. Optimizely, Inc. 1. Information We Collect

EU GDPR and . The complete text of the EU GDPR can be found at What is GDPR?

Privacy Statement for Use of the Trust Service of Swisscom IT Services Finance S.E., Austria

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information

IEEE GDPR Implementation & NTC

Platform Privacy Policy (Tier 2)

Data Protection Policy

Our agenda. The basics

Synchronoss Website Privacy Statement

The GDPR Are you ready?

Transcription:

General Data Protection Regulation April 3, 2018 Sarah Ackerman, Managing Director Ross Patz, Consultant

Introductions Sarah Ackerman, CISSP, CISA Managing Director, Cincinnati Responsible for overall engagement quality of services provided to clients Areas of expertise include information security, risk management, IT audit, and other related services Ross Patz Consultant, Cincinnati Areas of expertise include information technology management, disaster recovery, IT infrastructure engineering, information security, IT audit, and other related services 2

Today s Agenda What is GDPR? Who s covered? GDPR Key takeaways Privacy Shield 3

What is the General Data Protection Regulation?

What is GDPR? European Union s General Data Protection Regulation May 25, 2018 Comprehensive, uniform data privacy and security

Purpose GDPR was created to Set rules for processing of information Protect privacy Ensure free movement of personal data The protection of natural persons in relation to the processing of personal data is a fundamental right. European Parliament 6

Penalties Fines for non-compliance: 20M 4% of worldwide revenue Whichever is higher 7

Who s covered under GDPR?

Categories of Business Entities operating in member States International businesses with EU entities International catch-all clause 9

Covered Activities Data Controllers..the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data Data Processors a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller Data Recipients a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. Source: Official Journal of the European Union 10

Entities Outside the EU Two methods for transferring data outside the EU Adequacy decision Essentially reciprocity Appropriate safeguards The entity receiving the data can prove that it has controls in place to meet the GDPR standards for privacy 11

Organization of the Law

Organization of the Law Legislative Acts & Regulation Source: Official Journal of the European Union 13

Organization of the Law (cont.) Regulation 10 Chapters 99 Articles Very descriptive! 14

Organization of the Law (cont.) (37) A group of undertakings should cover a controlling undertaking and its controlled undertakings, whereby the controlling undertaking should be the undertaking which can exert a dominant influence over the other undertakings Source: Official Journal of the European Union 15

Organization of the Law (cont.) Chapter II Principles Relating to Processing of Personal Data Chapter III Rights of the Data Subject Chapter IV Controller and Processor Chapter V Transfers of Personal Data to Third Countries or International Organizations 16

Who Manages GDPR Supervisory Authority Appointed by each member State Ensures Law is applied equally and fairly Enforces Law within their State European Data Protection Board One representative of each Supervisory Authority Handles dispute resolution and overall governance US Regulators FTC Department of Commerce 17

GDPR: Key Takeaways

Changes from Previous Privacy Directives Increased territorial scope Including the cloud Consent Breach notification Right to access Right to correct; Right to be forgotten Data portability Privacy by design Data Protection Officers 19

Overlap Not a total re-write of existing program Some overlap with: NIST 800-53 Security and Privacy Controls ISO 29100 IT Security Techniques Privacy Framework AICPA s Generally Accepted Privacy Principles (GAPP) OCC s Privacy Laws and Regulations 20

To Do List Internal business analysis Create/update documentation: Decisions related to data processing Privacy and security policies (e.g., data storage) Data breach notification procedures Informed consent Review contracts (controllers/processors) Determine Data Protection Officer Education and awareness 21

Common Challenges Underestimating scope have you started? How to interpret What additional measures needed? Building/maintaining inventory of data processing Lack of capabilities For example, who to be Privacy rep in EU? 22

Future of Compliance Legislation in US Congress? Brexit similar to Switzerland? 23

Privacy Shield

Privacy Shield & GDPR Privacy Shield addresses privacy protections of GDPR Part of framework accommodates aspects of GDPR Covers methods of data transfer 25

Privacy Shield Overview Who does it apply to? US companies transferring data related to EU & Swiss individuals What does it cover? Provides mechanism to comply with data protection requirements (e.g., GDPR) When does it take effect? Now as soon as you self-certify Where is it administered? Why was it created? Administered: International Trade Administration (ITA) Enforced: US Department of Commerce (part of Federal Trade Commission) Also: Data Protection Authorities (DPA) European Commission Replace Safe Harbor 26

Privacy Shield vs. Safe Harbor Safe Harbor no longer recognized by EU Privacy Shield provides adequate protection Joining Privacy Shield will automatically withdraw from Safe Harbor As of September 2017: 2,400 organizations have joined Privacy Shield 27

Privacy Shield Principles Privacy Shield contains: Principles What you should focus on Letters Describes how FTC will run program and enforce 23 total Principles 7 commonly recognized privacy principles 16 supplemental principles Explain and augment first 7 Requirements cover: Use and treatment of personal data received from EU Access and recourse mechanisms 28

Privacy Shield Privacy Principles 1. Notice 2. Choice 3. Accountability for Onward Transfer 4. Security 5. Data Integrity and Purpose Limitation 6. Access 7. Recourse, Enforcement and Liability 29

Privacy Shield Supplemental Principles 1. Sensitive Data 2. Journalistic Exceptions 3. Secondary Liability 4. Performing Due Diligence and Conducting Audits 5. The Role of the Data Protection Authorities 6. Self-Certification 7. Verification 8. Access 9. Human Resources Data 10. Obligatory Contracts for Onward Transfers 11. Dispute Resolution and Enforcement 12. Choice Timing of Opt Out 13. Travel Information 14. Pharmaceutical and Medical Products 15. Public Record and Publicly Available Information 16. Access Requests by Public Authorities 30

Privacy Shield vs. Safe Harbor What s New? New privacy protections Notice requirements Accountability for onward transfer Purpose limitation and data retention Enhanced complaint resolution Response time Free dispute resolution Binding arbitration Ongoing requirements if withdraw and maintain data Improved cooperation and transparency 31

Privacy Shield Subsidiaries Must identify all entities, subsidiaries All subs must inform individuals about adhering to Principles 32

Privacy Shield How to Join 1. Confirm eligibility 2. Develop a compliant privacy policy 3. Establish Independent Recourse Mechanism (IRM) 4. Ensure verification mechanism is in place 5. Identify your point of contact 6. Self-certify 7. Reaffirm self-certification annually 8. Reply to inquiries 33

Privacy Shield Verification Self-assessment or third party Assess published privacy policy Periodic objective reviews of compliance Audit, random reviews, or technology tools Signed statement verifying self-assessment or outside compliance review 34

Privacy Shield Impact Increased regulatory focus Stronger obligations for data transfers Increased risk from third parties Respond to disputes faster Document and maintain records, compliance reports 35

Privacy Shield Self-Certification Supports administration, supervision, related services Annual fee to participate Annual Revenue Single Framework $0 $5M $250 $375 $5M $25M $650 $975 $25M $500M $1000 $1500 $500M $5B $2500 $3750 Over $5B $3250 $4875 Both Frameworks Annual fee if retain data after withdrawal: $200 36

Questions? If you wish to discuss any aspect of this presentation in more detail, please feel free to contact us: (513) 768-7100 sackerman@clarkschaefer.com rpatz@clarkschaefer.com www.clarkschaefer.com