1 of 40

General Data

Protection Regulation

(GDPR)

Compliance

Assoc. Prof. Dr. Thanachart Numnonda

Executive Director

IMC Institute

12 February 2018

2 of 40

Speaker

  • Executive Director, IMC Institute
  • Committee of the Council, Ubon Ratchathani University
  • Chairman, Siameast Solutions Public Co.Ltd.
  • Independent Director & President of Audit Committee, Thanachart Bank Public Co.Ltd.
  • Independent Director, Vintcom Technology Public Co.Ltd.
  • Independent Director, Humanica Public Co.Ltd.

2

3 of 40

Background

Sensitive personal customer information held by

business pose significant risk

if stolen and abused.

3

4 of 40

Source: GDPR Compliance: “Explain Like I’m Five” with Data Privacy Expert. YouTube

4

5 of 40

General Data Protection Regulation

  • GDPR
  • Specify how customer data should be used and protected.
  • Adopted by EU parliament in April 2016.
  • Enforceable throughout the EU on 25th May 2018.

5

6 of 40

Who does GDPR apply for?

  • Applies to everyone involved in processing data about individuals in the context of selling goods and services to citizens in the EU, regardless whether the organization is with in the EU.
  • Data controller. (EU employee, Finance, EU customers)
  • Data Processor. (Process somebody else data)
  • For example, SaaS, e-Commerce outside EU.

6

7 of 40

Data protection model under GDPR

Source: Preparing for EU GDPR, IT Governance Ltd

7

8 of 40

Source: Solving Critical GDPR Challenges, YouTube

8

9 of 40

Why everyone should care about GDPR?

  • Administrative fines up to 20 million Euro or 2-4% of worldwide annual revenue.
  • EU customer expectation. Are your company GDPR compliance?
  • Lose customers & Trust.
  • Competitive advantage.
  • More business effectiveness about your data.

9

10 of 40

10

11 of 40

GDPR: Personal Data

  • Name, DOB, national, email
  • Online identifier, cookies, IP address, GPS location data
  • Biometric, Religion, Ethnic
  • Health data, Financial data

11

12 of 40

12

13 of 40

Data Landscaping

A value based approach to documenting what you hold, why and for how long, where, where it came from, and with whom you share it, when (& where)

13

14 of 40

GDPR: Requirements

  • Consent
  • Breach notification
  • Right to access
  • Right to be forgotten
  • Data portability
  • Privacy by design
  • Data Protection Officers (DPO)

14

15 of 40

Consent

  • Consent must be clear and affirmative, companies cannot use indecipherable terms and condition with legalese.
  • It must be as easy to withdraw consent as it given.
  • Special condition apply for child (under 16)
  • Secure against accidental loss, destruction

or damage

  • Article 7-9

15

16 of 40

Breach notification

  • A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
  • In the event of a data breach, data processors have to notify their controllers and customers of any risk within 72 hours.
  • Article 33.

16

17 of 40

Right to access

  • Data subject have the right to obtain information from data controller of whether their personal data being processed .
  • Data controller should provide an electronic copy of personal data for free to data subject.
  • Article 15-16.

17

18 of 40

Right to be forgotten

  • When data is no longer relevant to its original, data subjects can have the data controller to erase their personal data and crease its dissemination.
    • Company need to where are customer data?
    • Data controller decide.
    • Need to prepare both business & technical
  • Should be able to Undo.

18

19 of 40

Data portability

  • Allows individual to obtain and reuse their personal data for their own purposes by transferring it across IT environment
  • Be able to move personal data from one company to another (include competitor)
  • Must be in machine readable format (e.g. CSV)

19

20 of 40

Privacy by Design

  • Call for inclusion of data protection from the onset of designing systems, implement appropriate technical and infrastructure measurement.
  • Privacy must now be designed in data processing by default.
  • Data processors/controllers not established in the EU must designated respectively.
  • Data flow audits, Data protection impact assessment (DPIA)

20

21 of 40

Data Protection Officers (DPO)

  • Professionally qualified officers must be appointed in public authorities, or organization that engages in large scale systematically monitoring or processing personal data.
  • Staff awareness training is also critical.

21

22 of 40

Impact of GDPR for business

  • Restriction on commercial data use
  • Compliance spending
  • Inspire trust and confidence
  • Safeguard customer data security rights

Source: GDPR - Simply Explained in 3 Minutes, YouTube

22

23 of 40

10 Ways to take action today

  • Assign a dedicated individual (or team) to focus on team.
  • Start listing all the systems that house data.
  • Determine if you a data controller or a data processor.
  • Understand the transfer of data between you and a third party.
  • Document personal data that is collected in each system.

Source: GDPR Compliance: “Explain Like I’m Five” with Data Privacy Expert, YouTube

23

24 of 40

10 Ways to take action today

  • Determine if automated data can be deleted (right to be forgotten)
  • Determine if automated data can be ported (data portability)
  • Consent: can you document and provide evidence that a user opted in to marketing programs?
  • Review security controls and determine what gaps exist.
  • Review the data breach plan.

Source: GDPR Compliance: “Explain Like I’m Five” with Data Privacy Expert, YouTube

24

25 of 40

GDPR preparation from IT perspective

Source: Virtual Session: GDPR without the Hype, YouTube

25

26 of 40

Classifications

Source: GDPR - ideas for analysing your data, YouTube

26

27 of 40

Source: GDPR - ideas for analysing your data, YouTube

27

28 of 40

Source: GDPR - ideas for analysing your data, YouTube

28

29 of 40

Source: GDPR - ideas for analysing your data, YouTube

29

30 of 40

Source: GDPR - ideas for analysing your data, YouTube

30

31 of 40

Source: GDPR - ideas for analysing your data, YouTube

31

32 of 40

Source: GDPR - ideas for analysing your data, YouTube

32

33 of 40

Source: GDPR - ideas for analysing your data, YouTube

33

34 of 40

Source: GDPR - ideas for analysing your data, YouTube

34

35 of 40

Source: GDPR - ideas for analysing your data, YouTube

35

36 of 40

Source: GDPR - ideas for analysing your data, YouTube

36

37 of 40

Dropbox's GDPR guidance

37

38 of 40

38

39 of 40

www.facebook.com/imcinstitute

39

40 of 40

Thank you

thanachart@imcinstitute.com

www.facebook.com/imcinstitute

www.slideshare.net/imcinstitute

www.thanachart.org

40