GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data...

21
GDPR Seminar 26 April 2018 – Hogeschool Leiden

Transcript of GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data...

Page 1: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

GDPR

Seminar

26 April 2018 – Hogeschool Leiden

Page 2: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Agenda

• INTRODUCTION

• GDPR WORKFLOW

• CASE STUDY

• HOW WE CAN HELP

1

Page 3: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

PIETER SCHERPENHUIJSENINDICA Founder, Technical Director & Lead Developer

2

STEPHAN IDEMAManager Forensic Technology at KPMG

Page 4: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

GDPR Workflow

3

(Procedures) (Data)

PIA Questionnaire

Data Landscape

Assess Privacy Risks

Mitigation

Scan,

Tag

& Report

Page 5: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

H company is a multinational company based in the Netherlands

H Company has 5000+ employees and 200+ business

partners worldwide

H Company has been gathering and maintaining

employee data for 25+ years

H Company is in possession of both

current & previous employee data

H Company is also in possession of

clients’ (B2B & B2C) data

Case Study- H Company

4

Page 6: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

GDPR Workflow

5

(Procedures) (Data)

PIA Questionnaire

Data Landscape

Assess Privacy Risks

Mitigation

Scan,

Tag

& Report

Page 7: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Data Protect Impact Assessment (PIA)

6

Data Protect Impact Assessment (PIA) is necessary prior to the implementation of

data processing systems or activities that comply with the General Data

Protection Regulation (GDPR)

Describe the nature, scope, context and purposes of the processing01

Assess necessity, proportionality and

compliance measures02

Identify and assess risks to individuals03

Identify any additional measures to

mitigate those risks04

Page 8: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

What about my data?

7

Structured Data

Unstructured Data

Page 9: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

What about my data?

8

Page 10: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

GDPR Workflow

9

(Procedures) (Data)

PIA Questionnaire

Data Landscape

Assess Privacy Risks

Mitigation

Scan,

Tag

& Report

Page 11: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

10

CRM

File shares

Databases

Email

DMS

Data Landscape

Structured data is easy, but how to handle the unstructured data?

Page 12: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

GDPR Workflow

11

(Procedures) (Data)

PIA Questionnaire

Data Landscape

Assess Privacy Risks

Mitigation

Scan,

Tag

& Report

Page 13: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Initial Report - Overview

12

The Overview page provides the real - time information about the personal data

stored in your company and shows your progress in resolving GDPR issues

Page 14: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Initial Report - Landscape

13

The Landscape page provides you with privacy risk map and illustrates the

personal data distribution across your company’s infrastructure

Page 15: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Initial Report - Issues

14

The Issues page contains a full list of privacy issues and the graphs on the right

side represents your total progress

Page 16: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

GDPR Workflow

15

(Procedures) (Data)

PIA Questionnaire

Data Landscape

Assess Privacy Risks

Mitigation

Scan,

Tag

& Report

Page 17: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Assess Privacy Risks

Unlawful processing of

personal dataAuthorization risks Data Retention Risks

• Processing of personal data for

which there is no legal ground

• Processing of personal data

that does not align with the

original purpose of processing

• Processing sensitive personal

data where no consent is given

• Access to unstructured data is

not managed

• Unauthorized access to

personal data

• Access to personal data is

inconsistent with corporate

policy

• Personal data is stored after

the retention guidelines

• Processing of personal data

for which there is no legal

ground

16

Page 18: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

GDPR Workflow

17

(Procedures) (Data)

PIA Questionnaire

Data Landscape

Assess Privacy Risks

Mitigation

Scan,

Tag

& Report

Page 19: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Mitigation

18

Unlawful processing of

personal dataAuthorization risks Data Retention Risks

Policies and Procedures with

regards to data processing

Awareness & Training of

Personnel

Data Monitoring &

Dashboarding

IAM Processes & ProceduresSetting up data retention

schemes

Implementing data

retention IT controls

Page 20: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

REPEAT

19

(Procedures) (Data)

PIA Questionnaire

Data Landscape

Assess Privacy Risks

Mitigation

Scan,

Tag

& Report

Page 21: GDPR Seminar - Hogeschool Leiden · 2018-06-01 · Data Protect Impact Assessment (PIA) 6 Data Protect Impact Assessment (PIA) is necessary prior to the implementation of data processing

Thank you!

INDICA Team

www.indica.nl

T. +31 30 227 0160E. [email protected]

INDICA NL B.V.Groest 106, 1211 EE HILVERSUM, The Netherlands