How to Prepare Your Organization for GDPR

64 views
•
May 14, 2019
by
RSAC Cybersecurity
YouTube video player
How to Prepare Your Organization for GDPR

TL;DR

Prepare for GDPR by identifying every use of EU residents’ personal data, documenting its purpose and consent, enabling access and deletion requests, securing the information, and planning breach notification within 72 hours. Compliance also requires clear privacy notices, trained employees, reviewed vendor contracts, and controls for transfers outside the European Economic Area.

Transcript

So ladies and gentlemen, um, for the purposes of this seminar, we have assumed that you are having varied knowledge of, knowledge of GDPR. So some people have been working, as Laura said, for years. Um, some people have been working this year. I hope that not many people have been working on it the last thirty days for the first time, but there is ... Read More

Key Insights

  • GDPR is a regulation that replaces the earlier EU data protection directive and seeks to harmonize data protection law across member states. Unlike the directive, which countries could implement differently, the regulation establishes legal requirements that affected companies must follow.
  • GDPR applies to organizations that hold or process personal data, including organizations located outside the EU when they collect data from EU residents. Its definition of personal data is broader than traditional personally identifiable information and includes categories such as biometric information.
  • Purpose transparency is a central GDPR requirement because organizations must tell individuals how their data will be used and why it is being collected. They must also be able to demonstrate consent and identify where the relevant personal data originated.
  • Data subject rights include the ability to access, erase, rectify, or remove personal data and to withdraw consent. Organizations therefore need operational processes capable of locating the relevant information and carrying out these requests rather than treating compliance as a policy exercise alone.
  • Personal data security can involve encryption, tokenization, or obfuscation, depending on the organization and its systems. The underlying requirement is to protect personal data appropriately, building on security responsibilities already found in existing data protection rules.
  • Employee education is necessary because compliance depends on the people who actually handle personal data, not only executives and leadership teams. Staff members need to understand the importance of protecting the information and how the regulation affects their everyday responsibilities.
  • Third-party oversight is critical because both data controllers and data handlers can face liability when a handler suffers a breach. Organizations should vet vendors, examine the wider supply chain, and revisit agreements governing how outside parties process personal data.
  • Breach response requires notification to regulators within 72 hours when a breach involves personal data. Organizations must also examine international processing arrangements because GDPR requirements can apply to third parties outside the EU and transfers beyond the European Economic Area.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is GDPR and how does it differ from the previous EU directive?

GDPR is a data protection regulation that replaces the previous EU data protection directive. The directive functioned as a recommendation that each of the 28 member states could implement differently, so data protection rules were not uniform. GDPR is presented as a law intended to harmonize data protection requirements across those member states, making compliance mandatory for organizations within its scope.

Q: Which organizations are covered by GDPR?

GDPR applies to organizations that possess or process personal data within its expanded definition. Its reach is not limited to organizations based in the EU. A company located elsewhere in the world is also affected when it collects or processes data from EU residents. The broader definition means that some organizations may encounter new obligations even if they already follow existing data protection regulations.

Q: What information counts as personal data under GDPR?

Personal data under GDPR covers a wider range of information than traditional personally identifiable information. The presentation specifically identifies biometric information as an example of data included within this broader scope. Organizations should therefore avoid relying only on their previous understanding of personally identifiable information and instead determine which data they collect or process falls within the regulation’s expanded category.

Q: What must organizations tell people when collecting their data?

Organizations must explain how an individual’s data will be used and identify the purpose for which it is collected. Compliance is not limited to obtaining consent. The organization must also be able to prove consent and show where the information came from. These requirements connect data collection to a clearly communicated purpose and make documentation an important part of the compliance process.

Q: What rights do individuals have over their personal data?

Individuals have data subject access rights that include accessing their personal data and asking for it to be erased, rectified, or removed. They can also withdraw consent. Organizations need processes that can receive and complete these requests, which requires more than publishing a policy. They must be able to find the affected information and perform the requested action within their operational systems.

Q: How should an organization protect personal data under GDPR?

An organization should maintain appropriate security for the personal data it holds or processes. The presentation names encryption, tokenization, and obfuscation as possible approaches, without prescribing one universal method. Security also depends on educating employees who handle the information, since staff throughout the organization need to understand why protection matters and what the regulation requires of their work.

Q: How does GDPR affect third-party vendors and contracts?

Third-party vendors form part of the organization’s data-processing chain and therefore require careful oversight. If an organization acts as a data controller and a vendor acts as its data handler, a breach at the handler can create liability for both parties. Organizations should vet vendors, examine supply-chain relationships, and revisit contracts to ensure that personal data responsibilities and processing arrangements are properly addressed.

Q: What should a GDPR breach response process include?

A breach response process should enable the organization to identify when an incident concerns personal data and notify the regulators within 72 hours. Because the deadline is short, organizations need preparation before an incident occurs. Their planning should also account for third-party handlers, since a vendor breach can affect the controller, and for processing relationships that extend beyond the EU.

Summary & Key Takeaways

  • GDPR replaces the previous EU data protection directive with a regulation intended to harmonize data protection law across member states. Its scope extends beyond traditional personally identifiable information and applies to organizations outside the EU when they collect or process personal data belonging to EU residents.

  • Organizations must tell individuals why their data is collected and how it will be used, while retaining evidence of consent. They also need processes that let individuals access, erase, rectify, or remove their data and withdraw consent. Privacy notices should communicate these practices in language ordinary people can understand.

  • Practical preparation includes securing personal data through methods such as encryption, tokenization, or obfuscation, and educating employees who handle it. Organizations must also examine their supply chains, reassess third-party contracts, control transfers outside the European Economic Area, and establish procedures for notifying regulators of qualifying breaches within 72 hours.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚