Having issues accessing the video above? Watch the video here.
GDPR Basics: The What, Why, and How
In this webinar, SecurityMetrics' David Salazar, SMB GDPR Sales Team Lead, covers:
- GDPR Basics
- Why the GDPR is important
- How to meet GDPR Requirements
This webinar was hosted on October 10th, 2018.
GDPR Basics: The What, Why, and How Transcript
Well, at this time, we're gonna go ahead and get started with GDPR basics.
I'll turn the time over to David, and we'll get going. Thanks.
Thanks for the introduction.
Hi, everyone.
Like Andrew said, my name is David Salazar, and I I work here with a couple sales groups, and we've been focusing a lot on GDPR compliance recently. So I'm excited to talk about the what, why, and the how, and some of the basics involved with GDPR.
So to start off, I'll give you guys this little quote right here.
It takes twenty years to build a reputation, a few minutes of cyber incident to ruin it. So I'd like you guys to keep that in mind as we're going through the webinar today and some of these slides. Just kinda think about some of the recent things that have happened, in the past couple months.
So for our agenda today, we will be, talking about how GDPR compliance impacts you.
We'll do some clarification on the GDPR requirements, and we'll go over some of the best practices.
And a lot of the common questions that we encounter here at Security Metrics, revolve around the type of stuff that we we will be talking about today. So what is GDPR?
GDPR stands for the General Data Protection Regulation.
The e the EU general data protection regulation, replaces the EU's data protection directive and was designed to harmonize reshape the way organizations across the region, approach data privacy.
The key articles of GDPR, as well as the information on the business impact, can be found, throughout our site on it.
And so GDPR took about four years of preparation.
It's finally approved by the EU Parliament on April fourteenth twenty sixteen, and it had an enforcement date this past May twenty fifth twenty eighteen.
So, like I said, in the UK, the GDPR, will replace the nineteen ninety eight Data Protection Act.
And what GDPR is essentially doing is, different countries across Europe, we're doing different things for data protection.
GDPR will unite everyone under one regulation.
So why should I care?
There are potential fines.
That's kinda that's a question we get a lot, and there's a lot of concern we get about the fines.
Non compliant organizations, they can be fined up to four percent of annual global turnover or twenty million. So there's a tier tiered approach to the fines. For example, a company can can be fined two percent for not having their records in order, not notifying the supervise supervising authority, and data subject about a breach or not conducting an impact assessment.
So that's the maximum fine that can be imposed for the most serious infringements, not having sufficient customer consent to process data or violating the core of privacy by design concept. So it's important to note these rules apply to both controllers and processors, meaning clouds will not be exempt from GDPR enforcement.
I'll I will review a couple. So we have this marketing agency that was recently fined sixty thousand euros for sending one point four two million emails without consent.
Recently, you probably noticed some other companies in the news, facing some fines. The biggest ones probably being Google and Facebook. They're facing up to nine point three billion in fines.
The next data I do wanna cover this data breach. It's a little older.
But after the car phone warehouse was breached in twenty fifteen, the information commissioner Elizabeth Denham said, a company as large, well resourced, and established as Carphone Warehouse should have been actively assessing its data systems and ensuring systems are robust and not vulnerable to such attacks.
Carphone warehouse should be at the top of its game when it comes to cybersecurity, and it is concerning that the systemic failures that we found related to rudimentary commonplace measures. So, they lost three million customer records in twenty fifteen.
They had a fine of four hundred thousand euros assessed, and they were also fined under the EU Data Protection Act. So it's really important to have all the measures in place to prevent any data breaches, fines, or, at the end of the day, any unhappy customers.
Next, we'll cover a couple terms to know. There's a lot of terms for GDPR, but we find these are kind of the main ones to know. So we'll briefly go over all of them and and their roles. So data controller. So a controller is an entity that decides the purpose and manner that personal data is used or will be used.
Data processor.
The person or group that processes the data on behalf of the controller.
Processing is, obtaining, recording, adapting, or holding any personal data.
And then a supervisory authority is independent public authority, established by a member state to represent the people and oversee and monitor businesses.
So those are some of the main terms we find here at Securier Metrics. So hopefully, that gets you a little familiar a little more familiar with some of the the terms you'll encounter in GDPR.
So next, we're we're gonna cover who enforces GDPR.
So supervisory authorities are responsible for issuing fines.
It does not say anywhere that the fines are independently commune cumulative.
It is assumed that the maximums are maximum across all EU entities.
In the UK, the information commissioner's office or the ICO is a enforcer.
And in the US, yeah, the US is US companies with a physical presence in the u EU, are also required we do wanna touch up on a few, So we do wanna touch up on a few, GDPR requirements, kinda give you a guide what, an idea of what is expected of each business to complete.
So the first step in GDPR compliance effort is discovering and clearly documenting all of the PI data that flows into and out of your organization.
It's amazing how many places PI can get to when you do a detailed analyst analysis of what kind of data you get and from where.
Data discovery and mapping is a basic principle of all data security efforts.
You can't protect what you don't know is there. The process consists of assigning a person or a group with the task of going through all departments and groups in a company and searching for pie with various tools, conducting interviews, reviewing documents, mapping privacy information.
So privacy notices must be transparent, using clear and plain language, easily accessible.
You should be ready to explain things like why you need the data, your data retention periods, the data owner rights.
And then we'll touch a bit about individual rights.
So it's not all the rights, just a few of them that we we get questions about. So we will I'll review a few of them right now. The right to portability.
So users may request a copy of personal data in a portable format erasure.
Data subjects have the right to request for their data to be deleted. To be compliant with GDPR, businesses must honor honor these requests. The right to object. Individuals should be advised that they have the right to opt out of direct marketing.
Profiling. An individual has the right to not be subject profiling, and profiling for market purpose marketing purposes will always require explicit consent.
So what is your action? It's to design and define processes to fulfill these rights and to document it.
The next requirement we'll go over is lawfulness for processing data.
Basically, you need to explain your company's need to obtain the pie.
It needs to be legal, document, and made it accessible to individuals whose data you gather.
Consent to process data. So gathering data needs to be an opt in, not an automatic take, and do a quick pop up in to inform or have something on your website somewhere that says, if you enter data, you're consenting.
Make sure your your process considers this and makes modifications as necessary to make it a clear opt in choice by individuals.
Record this choice in logs.
This choice can't be slipped into a big term or a condition state statement. It needs to be separate. So make sure you have clear, concise privacy notice documentation available to all individuals.
Do you have the ask yourself. Do you have the following attributes in your consent process?
Consent is an explicit opt in, not inferred.
Consent must be separate from others agreed to terms or condition.
Valid consent must detail the type of data collected and for what purpose.
Consent for children must be given by child's parents or or custodian, and consent must be proven as opt in, and consent can also be withdrawn.
Data breaches. So failure to report a breach when required to do so can always result in this in a fine as well as a fine for the breach itself.
So it's really important to establish policies and procedures to detect, report, and investigate personal data breach.
You must be you must report personal data breach breaches to SA with within seventy two hours after awareness of the breach.
If individuals face an adverse impact, you you need to contact those individuals directly.
And the final thing we'll cover here is, data protection officers.
So always designate a data protection officer.
They're gonna be responsible for your data protection compliance, and you always wanna make sure your DPO needs a couple has a couple things. They have knowledge, support, and they have the authority to carry out their role effectively.
So after going through a couple of requirements, what do I do now?
To get started on the GDPR, you know, we didn't go through every single requirement, so you'll definitely wanna get familiar with with a lot of the requirements, if not every single one. You wanna start working on those requirements and make the necessary changes in your policies and procedures.
And then you you you also wanna make or or buy that needed documentation.
And then we'll cover a little bit right here about general data security versus GDPR.
So GDPR encompasses basic data protection principles.
Compliance to other publicly regulated data security initiatives will help, but g d GDPR may require additional processes and policies, and it'll probably have some scope change.
A question we get asked here a lot at Security Metrics since, we're known mostly as a PCI compliance provider is if you're what's the difference between PCI and GDPR compliance?
Or if you're PCI DSS compliant now, are you done with the GDPR? And to be simple, no.
It's definitely a great start to be PCI compliant, and there will be some some overlap. But, generally, what we're seeing is the GDPR scope could be much longer. You know, it's not just credit card numbers anymore that we're worried about keeping secure. It's all personal information. So there is a quite a bit of, a little bit of more requirements since it it's not primarily focused on credit card numbers, but like I said, all personal information.
And then how can we help?
So there's a couple ways we can help.
We can help you assess your compliance with the guided checklist. So what happens is you access our portal, and it lists a a lot of the GDPR requirements, and it gives you the ability to track your progress, upload your documents, and it it really guides you through, some of the steps in place to be GDPR compliant.
We've talked about the next item a little bit. You could easily start building your policies and procedures.
We have some great customizable templates, and we can actually actually store those in your in our cloud for your easy access and help you really customize that to your business so you have the proper policies and procedures in place, track your progress.
So, if you look at this wheel right now, it tells you, what you have documented in our portal, what's implemented, what's not implemented.
It's a great we give you a great added glance on how much, the business needs to accomplish and how much they've accomplished.
Another great thing we do, we we talk a lot about personal information.
We have this great scan, that you install on your computers, and you can run it, and it'll find all the pie at your organization.
We find this, really helpful because you wanna know where all that all that personal information is. And with a quick scan, I branded on my computer, it takes five to ten minutes. It really helps you locate all that personal information so you can know what to protect.
The final thing we can help you with is, employee training. So we provide a lot of, self guided trainings on GDPR fundamentals because we find it's important for, not just the, like I said, the DPO to be, educated, but the whole staff as well on, you know, the GDPR fundamentals.
So we we provide that. You're able to access it online and really keep track on, what employees need training and who has completed any training.
And to end, I just wanna provide this quick, reminder for everyone in this quote. For every lock, there is someone out there trying to pick it pick it or break in.
Especially in our digital and our cyber era nowadays, everyone's always trying to find a way in. So it's really important to stay on top of, you know, anything we might have at a business and keep it secure, especially when it comes to our customer's personal information.
So I'll I'll if there's any questions, I'll give everyone five to ten minutes.
Feel free to chat those in, and we'll definitely answer those or, any other things you guys may have questions about.
Hi, everyone. So I just wanted to address one more thing before we leave for the day.
A lot of times we get the questions, I'm GDPR compliant. What do I need to do now?
I've done everything I need to do to protect personal information. I know where it is. I know what it is. I know exactly where it is.
So and that's great. That's definitely a good start. What we've been finding a lot, especially with our customers, is that, policy and procedures are not set in place. So it's it's very important to have policies and procedures in place because it'll give you exactly how you need to react, where you need to report, kind of all the steps that happen in case you run into any difficulties. So we touched on this a little bit before, but if you if you're if you have something in place for GDPR compliance and you're taking the steps, great.
Awesome.
You're you're headed in the right way. But if you don't have any policies and procedures, it's definitely something you wanna have in place to really take all the measures that you can take. So if you have any question on those, feel free to reach out to us. Give us a call. Let us know all your questions, and we can definitely dive into it and explain a little bit more about our policies and procedures and the positive effects it can can have on your business.
So thanks everyone for attending today, and we look forward to, meeting again in the future.
