Welcome to the DQS Inc. webinar GDPR Compliance: What You Need to Know?
Your speaker for today's program is Subrata Guha, Director of IT Services at DQS.
Participants can send questions at any time by using the Q&A window located on
the lower left of the presentation screen. Type your message in the bottom
and use your mouse to click the ask button to send it. A question and answer
session will follow the presentation. I will now turn the call over to Mr. Guha;
please begin. Thank You, Donna, and welcome all to this webinar on GDPR, and this is
my attempt to give you very simple interactions to a very complex subject.
We are all hearing a lot of buzz about GDPR, which is going into effect from
25th of May. It's a very high-level view of what GDPR contains, what it means
for an organization to become a GDPR compliant, and particularly for the
companies who are not part of European Union's like we are here in the United
States, but we have operations in Europe so what it means for us. So what's GDPR?
We all know that it's going to be a regulation starting 25th of May. It was,
however, issued the directives from European Union in 2016. It's all about
protection of personal data, and once it becomes a directive, it becomes a
regulation it will also harmonize the various data protection laws of the
various European nations it will be, all of them will be governed by one set of
rules, and it will allow the free movement of
data across the EU. And this is the first time it has been recognized as a
fundamental right of individuals to demand the protection of the
personal data. So moving on in GDPR governance, how the whole thing will
be governed? There will be a European Data Protection Board which will be the
highest level of governing body to enforce GDPR requirements. Every member
country will set up a supervisory authority under their public system. They
can have more than one supervisory authority in that case they have to
identify one supervisory authority as the lead authority for that country.
The Data Protection Board will comprise of representatives from each of these
supervisory authority members. If we look inside the GDPR, we all know it is a
related privacy standard, but in that addition to the individual data privacy,
it's also stipulating requirements for data protection and data security and
also governing rules to manage and govern the GDPR implementation. But
important things here to note that GDPR does not provide any security controls
for data protection or data security. So here organizations have to fall back
to security standards like ISO 27001 or least 853 or PCI DSS,
to ensure data protection and data security within their organization. Now
if you download the text of GDPR it is the 261 page documents, there are
various websites from where you can get this information, so one is given here
in the footnote now the whole document has two parts:
the first half, which starts on page 22 to 108, which defines the actual text of
the regulations in 173 paragraphs or 173 sections,
whatever you may like to call it. It's it uses the term should and it gives you
in the form of a detectives to the organization's what they have to do and
probably that would be used when it when there is a situation of litigations, or
administrative fine is being imposed, then your violation will be cited
against the appropriate section of the regulations. However, if an organization
like to implement GDPR the actual requirements of the GDPR stipulated
in the second part of the document under various articles. So there is article 1
to article 99, and they're grouped into various sections or various chapters
based on the similarity of the articles. So it will find the article from
chapter 1 to chapter 11, and the article statements are using the verb shall and
the people who are familiar with the ISO areas, where the ISO requirements are
stated using the statement shall. So in these articles, it will see under each
article the organization shall ensure things, an individual shall have rights
to ask for access to the data, and so forth. To give you a big picture of the
GDPR organization, here's the table of contents which gives the chapter numbers,
the title of individual chapters, and how many articles are provided with that. So
for example, chapter 1 is the general information which talks about scope,
applicability, various definitions. Chapter 2 talks about the principles of data
problem, data processing from Article 5 to article 11. Chapter three has
multiple sections; section one talks about transparencies and modalities..
Section two talks about information and access to personal data and the
corresponding article numbers that provided. Chapter four is about the
control of the data protection; here it talks about controllers and the
processes role, security of personal data, data protection, impact assessment, and so
forth. Section 5 is on the transfer of personal data to in the non-EU country, and
article 44 to article 50 is dedicated for that. What it will notice from Chapter 6
to chapter 11 is all about setting up governance, and supervisory authority,
various rules of running those authorities, the consistency among
various organizations, and it ranges from article 51 to 99. So almost half of
the articles are delegated towards governing and Management Act of that.
For the interest of the audience, what I've tried to focus more in this topic
intercession is section two, three, and four, and, of course, five. Let's start
some important definitions, so whenever we talk about personal data,
typically tend to think a sensitive personal data or in other words which are
called PII or personally identifiable information, which is like my social
security numbers or EPHI or electronic personal health information.
Article 4 defines personal data, and if you read the
definition it's very broad it says any information that can identify a person
such as a person's name, address, phone number, or a unique identifier. And
interestingly a couple of weeks back I was checking in a Hilton Hotel and the
first time I realized that after the front is lady completed the check-in
formality she handed me of a key envelope and said that your room numbers
written inside that, and earlier they would say aloud that you are in second
floor room number and so on. And this time she mentioned that we have a new
data privacy policy in place and we are not allowed to say your room number
aloud. So my room number is private information, so that's the indication
that to what extent this is covering personal data. Of course, there's an
article 9, which has a separate section which talks about spatial categories of
personal data which includes my bio-metric data or genetic data or social
security number. So those are uniquely identifiable information, and there are
separate provisions for processing those. Also we were to understand that term
processing, because generally in an English meaning when we use the word
processing, we tend to think about manipulations of data like we are doing
something with the data. Running by payroll, we are computing something out
of that. But here the definition of processing is as simple as collecting
and storing and transferring someplace or if you are running a query
to retrievals. There host of other definitions available but I felt this is
important for us to be on the same page to understand the scope of GDPR
to be clear about the definition of this tool. There are three terms which are
frequently used through throughout the text of GDPR it is a data subject,
data controller, and data processor. A data subject is in EU national whose
data we are handling endoscope. If they are also referred sometime within the
text as a natural person. The data controllers are the organization or a
group of people who needed to collect personal data for processing so
that it can be an organization; it could be in the hospital, it could be a charitable
organization, as long as that body is collecting personal information for some
purpose they are considered as a controller. Now today's scenario very
often when you're storing data this data is being stored in an application which
is hosted by a third party or hosted in the cloud, now that party is now
considered as a data processor which is a different entity than the
organization which collected the personal data. There could be situations
when an organization is hiring a payroll company to run is payroll, so in that
case, the payroll company is also a processor. So these three terms will
be used frequently across the text of GDPR.
The whole GDPR is based on the six fundamental principles of data
processing and which is defined in article 5. The first principle is the
process lawfully, fairly, and transparent and I will get to it in the next slide
which is itself is an article, article 6 the second principle which is called a
purpose limitation is that you will collect data when you definitely have a
need to collect it, as a legitimate purpose it's not collected for any
academic interest, just to collect for the sake of collections. Principle 3,
which is related to principle 2, which is called data minimization is that you
click exactly what you need to collection collect more than what you don't
require. And a very common example welcome across that you go to your place
you are required to fill out a form so that you give your name, postal address,
your telephone numbers, and then email address and there will be a question
asked that what is your preferred mode of communication by email, telephone
number, or by a regular mail, and you check email. So if you're collecting
this information only for communication, then you first ask the
question that what is your preferred mode of communication and collect only
that. So if you are only using my email while, you're collecting my phone number
or my postal address. Number 4 is the accuracy principle, that if you're
keeping my record, keep it up to date as it changes, and I don't know how many of
you have encountered but I have pretty often noticed that in a pharmacy, my doctor has
changed the strength of my medication from 50 milligrams to 100 milligrams and you
go back, and you find they still have two prescriptions for you, one for 50
milligram and other for 100 milligrams. My doctor's records I found very often they
have not included my last blood test reports. So
this is the principle of accuracy that if you're maintaining data, you have to
keep updating your record. This profile is stored only for the duration you
need to store that. When you move from one doctor's office to another doctor's
office you transfer your records, now what is going to happen in your previous
office are they going to purge your data? If you leave one employer go to another
employer, what is happening with your data or the personal files
to retain by you the previous employer? This is not always clear. So here we will get
to the right section very quickly that it says that you have a right to ask
them "now I'm leaving just delete my information." Principle 6 talks about the
security which is when you're processing data you have to ensure security
integrity and confidentiality is the security element. Now, what is the
personal use principle number 1, which is article 6, talks about processing is
lawful under following conditions. If any one of these applies, it will be
considered as lawful. A data subject has given consent, and we are all familiar
with agreeing to your privacy requirements or giving consent to
something; we will get to that in the next sections about the requirements
these are finer details of consent. The number two is the processing is
necessary for the performance of a contract, which if you are working for an
employer have to pay your salary at the end of the month or bi-weekly, so
it is a contractual requirement to process your payroll,
depending on your pace, you known frequency. The third principle it is required
to fulfill in legal obligations that sometimes at the most company the HR
has to report some employee data to the Department of Labor, this is to fulfill a legal obligation.
Sometimes it is to protect the vital interest of an employee,
which is deemed that you have to deposit your Social Security
tax, you have to deposit your 401 K contribution, and this is all to
protect your interest. The processing is necessary to perform the tasks carried
out in public interest; there could be the public department can ask for
personal data your law enforcement or judicial departments and an employer
hazard I'd have to turn over your records to that agency because
it is considered under public interest. The last one is the processing is
necessary when it is a legitimate purpose the interest of the company to
turn over your record to third agencies, for example, you often know
times if you are falling behind on your payments on your credit cards and
bills your records are turned over to a
collection agency, this falls under the last requirement of that. We talk about
consent, and we are all used to consent article 7 has dealt with in a great
detail that what consent should mean. One distinction to remember here they're
very clear to sales that you have to provide consent for each of the data
items you are sharing with the controllers like your name, address,
telephone number, Social Security number, credit card numbers, or whatnot. And you
have to provide consent that okay you are okay with sharing your name and
address, but you are not okay sharing your telephone numbers with
someone else. So if you have to bundle up your constant into one record, the record
should be suitably formatted or structure so that it is very clear to
see what you have consented to and what you are not, and it is obligations of the
controller to retain documented information on your consent.
It can be still checking a box, but the subject of your content
should be written in a clear and plain language. And you have the right to withdraw
your content at any time. Nothing different for children's consent,
here (USA) age is stipulated as 16 years there is some
relaxation given to the member countries that it can go below 16 years,
they can reduce the age of concept below 16 years, but they cannot go below 13
years under any case. Now let's move to the area of right of the data subject,
and this is what is something we are not very used to in this country that when
your data is being collected, you are aware of what are your rights.
Article 13 which talks about the rights very clearly, it's the controllers have
to inform the data subject that intended use of personal data, every piece of data
which you are collected, what is going to be the use of that. How long personal
data will be stored, that goes to the retention period of your data?
Who all within the company will have access to your data or is there anyone
outside the company will receive any or all of your data? Whether
your data will be transferred to another country or outside of EU,
you will be told very clearly that you have a right to withdraw your consent.
You have the right to access your information at any time when it is stored
within that organization and here I have an examples where I've had a
situation, again in a doctor's office, where they moved to a new information
system and they send out a notification that all of their information in their
old systems has been archived and those all be readily available if you request for.
But here is even if archiving is not an excuse to deny access to information.
Even if it is archived, you have a right you can give time, and it
also gave a time limit that it has to be within 30 days of the data request.
You cannot be charged a fee to provide your information which you are
requesting for? Here in this country we have some new situations like you can
always have a right to ask for your credit report, you can get a free credit
report once a year, but that's the restriction that you can ask for only
one. Then you can also request for rectification if you see anything wrong
in your personal information which we can do we know that in the credit
reporting agency you can point out some errors in your credit reports and you
ask them for rectification, but you have the same rights maintained by your
doctor's office or your employer or any other place where you have shared your
data. And you also have a right to request to be forgotten
that you no longer once you record to be maintained in their organization
and that organization is obligated to show you some evidence that
your data has been purged or if it is a physical document which has been
securely disposed of. You should be informed that you have a right to
complain and as the mix of contact, you have to provide them
the contact details of who is the local data protection officer of the company
or the concerned person who to complain about. This is not exhaustive there are so
many other things, but I wanted to highlight, three of those which I felt
that these are important. Article 21 very specifically says that every data
subject has a right to object processing of personal data. Now 21 and 22 it goes
hand in hand, number 121 if it is raised that right to object if you know your
data is not accurate you can you can you can request the processing
organization to stop making further processing till it is corrected. Article 22,
it is the question of profiling, and I'm sure all of you who have filled out a
survey last few questions, which is often marked as an optional but it collects
the data regarding your race, ethnicity, religion, I'm never sure what is the
purpose of collecting tools information. And I guess the one something is being
done is some kind of profiling when they interpret the survey result they
try to do the profiling on that based on this age group or this on this ethnicity,
that is what is a response typically. Article 22 specifically says that you
can object to be part of any kind of profiling Article 3
laid out some form of restrictions, which typically say that all the rights
of data subject which have been laid out in these regulations and state can get
in waiver for certain circumstances, and some of them are national security,
defense, or the case of a public safety or law enforcement. So in some of the
place it is also mentioned that when GDPR is being implemented some of the
data which is excluded from the GDPR protections; those are the data collected
by law enforcement, border security, and those goes in line with this rationale
that if your data is required for a reason for securing
national security or for national defense, then you cannot claim you
safeguard under your rights of a data subject that no you don't want like to
share your data to the law enforcement, those are exempted. Now so far we have
been talking about the is the crux of the privacy element of it, now once your
data is now collected by a controller or being given to the processor. The
controller and processors are responsible for ensuring data protection
and data security. All it says that the controller, article 24, it says that
controller has to assess the risks related to the personal data which
they're collecting, and they are responsible for taking adequate technical
or organizational measures to demonstrate that you are complying with
the GDPR, and I will come back to it later on it says it kept on saying the
using the word technical and organizational nations, so it's just not a tool,
it has to have a tool along with the governing process is the source a management
system to make sure that the process is working. And article 25 says data
protection should be by design and by default. When the controller is engaging a
processor or controller is not solely responsible for holding the personal
data that the processor is involved. Article 28 talks about the controller and
processors, in that case, the controller had to make sure the processor has
adequate safeguard of the personal data to be in compliance with GDPR.
There has to be a contract in place between the controller and processors
which lay out the terms and conditions of the contract and the processing. If
the processor is outsourcing, in turn, to another subcontractor or another company,
then the whole requirements of data security should flow down, and the
processor will be responsible for ensuring the security of his or her or
their subcontractors. So it is a flow down requirement going from the
controller to the processor to the subcontractor, and it doesn't matter
whether processor or controllers are within the
EU boundaries or outside of EU. So if you are in on you country collecting
personal data of EU citizens you are liable to implement GDPR privacy and data
protection and data security requirements. Next part is
security part, Article 32 talks about security of the processing and here in
the document it only has given reference as a technique of ensuring security,
saying the use of encryption or used to try pseudonymisations where you're
trying to hide an employee's or person's identifications through encryptions or
by using some kind of a code system. And you adopt appropriate mechanisms based on
the risk you're encountering for that system. It doesn't go further on that,
and that's what I was saying that you have to now fall back onto is security
standards like 27001 or new standards. To look at the best practices to implement
security and some of the things which is the basic principle of security is to
maintain confidentiality, integrity, and availability and how you do that you do
it through access control, segregation of duties, setting around the code of
conduct, ensuring compliance to the code of conduct, and the whole nine years of
information security. What is stipulated here in article 33 and 34
is that the communication about a breach. The breach notification hour is
given 72 and the 72 hours has been set considering the scenario that if a breach
happened on Friday you have to make a notification on Monday so having the
weekend in between giving good extension, up to 72 hours, and this is being
considered as a very stringent requirements and I am not aware of US we
have regulations of bridge notifications within any time frame or if in effect is
the time frame it's much longer than 72 hours. And this 72 hours
notification is to all involved in that and article 34 specifically talks about
communicating to the data subject or subjects who are compromised in this
bridge. So as I said before that under the context of security, it had not provided
any security controls, but it has provided some requirements which they are expecting
the organization to comply with. Article 35 talks about a data protection impact
assessment, in short, it says DPIA. Here organizations are expected to conduct a data
protection impact assessment under certain conditions and some of the examples which
are given that you are starting anew processing system so you are moving into the new
ERP based system from an old legacy applications or you have been doing it in-house,
and now you are outsourcing some part of your processing. So you have to do a data
protection impact assessment, and this data protection impact assessment is a
two-phase assessment. The first assessment is to assess the new situation whether it
has any gap, the new situation could be a new system or a new processor and their
current processes what gaps they have with the GDPR requirements which is kind
of "gap assessment," and then you do a risk assessment. The risk of a potential impact
on data security arising out of the gaps which you have just found out. It is not very
hard and fast at this point that what are the situations where you have to it is mandatory
for you to do it then data impact assets and it has been left the supervisory authority
of the individual countries and they will identify certain situations and publish a list of
some operations in some situations where it will require a data protection impact
assessment. The second thing it has talked about a specific role in article 37 which is
called a data protection officer or DPO. A data protection officer should be assigned to
a company which has a business, and it has given a situations where you are handling
in large-scale spatial categories of personal data spatial categories are basically your
sensitive data which we considered as a TII or EPHI so if you are handling a large scale
or personal sensitive personal data you are required to appoint a person as a DPO or
a data privacy officer you can call it anyway whatever name you to like to do but that's
what is the designation. Or you are not dealing with the sensitive data, but you are
in the business of handling large scale of data which require regular and systematic
monitoring you may you have to identify a person which is called a DPO. There is set of
requirements specified that what should be the typical roles and responsibilities of a
data protection officer it also allows that if you are a multinational corporation, you can
have one corporate level DPO which managing everything, or you can have extra officers
supporting your corporate DPO. It is also specific requirement that if you are a company
outside of EU but you have a branch office in EU, so you are now within the purview of
GDPR are you have to identify somebody from your operations in EU nation to act as a
DPO or data privacy officer to fulfill that obligation. The Data Protection Officer should
also be free from conflict of interest so the person who has a direct responsibility of data
processing or data storing very common position is the CIO or somebody from the IT
departments cannot act as DPO. HR is another potential area which is controlling all
this personal data, so somebody from the head of HR cannot be a DPO. So DPO should
be independent, and the DPO is obligated to report to the supervisory authority in case
of any breach or any-compliance. So has a prohibition for certification which is in article
32 it says the certification will be established within the European nations it will be a
voluntary program is also the certification would be a three-year value DT but hasn't
spelled out exactly what certification mechanism it would be. It also mentions that
there should be a provision for providing a data protection sale or data protection
mark to show that this organization has implemented or showing compliance with the
GDPR regulation, but it also says that having a certification does not absolve data
controller from the liability of any violation if that may have happened within the
organization. So you cannot say that you're not liable if there is a data breach and
you have a certification you can be exempted from the impact of the data breach.
In absence of an existing certifications came most of the organizations they are trying
to use something which is already working in the same area common example is an
ISO certification which also forms in the same frame of a three-year validity has a
surveillance system which is the ongoing monitoring so it could be a replacement till
the EU nations comes out for which specific certifications came under this GDPR
regulation. Here comes of transferring data outside of European Union, the bottom
line is that if you're transferring data outside of EU, you could be a controller or you
can be just a processor now you're subjective GDPR, so you have to ensure an
adequate level of protection as stipulated into GDPR regulations. So article 44 just
says that the plain and simple you are obligated to these but before you, whether
you were allowed to do that or not which is defined in article 45. What is says that
European Commission will do a review of the geopolitical situations of different
countries and come up with a list of nations where the EU fails has sufficient data
protection mechanism in place, and they will publish this list on the website, and as
of this morning I saw on this website, they have about 12 company countries listed
on that site including the United States but there is a caveat, United States has the
data portability agreement with EU under the privacy shield agreement, and the
privacy shield agreement was done keeping in mind the data protection directives
which was issued in 2016 by EU now unless privacy shield is updated to be compliant
with the GDPR, the US will fall out of this list. So if our privacy shield requirements
are not updated and agreed by EU that now it is non-compliant with GDPR, the
companies in EU will not be able to transfer data to the US but it is expected since
everything is being updated and privacy shield is already in place so it will also
eventually be updated with the same timeline, so that continues to enjoy this
freedom of having free movement of data from EU or the portability of data from
EU to this part of the geography. Article 50 is also saying that the EU Commission
will set up a mechanism with non-EU nations on how to facilitate effective
enforcement of GDPR. In the last part which is kind of creating all these fears of
penalties and fines and those are the other provisions article 82 says that any data
subject whose data is compromised and it could have been material or non-material
damage, they're libel, they can expect compensation from the controller and
processors and any infringement it will be decided it was whose fault it is and there
the end they have delegate compensation from them. But in addition to that
compensation, there is also provided for in administrative fees which are defined in
article 83. And based on the circumstances your fees could be as high as 10 million
euro or 2 percent off and will turnover whichever is higher and the next bracket says
the 20 million euro or 4% of annual turnover whichever is higher and there are various
conditions involved in that it will go with it daily of offense is your first violation, so
you deserve a beat offender whether you have done a data protection impact
analysis or you ignored that steps all these things will get into deciding the number
rules for additional penalties. It's not clear that whether all three will apply or any
rules for additional penalties. It's not clear that whether all three will apply or any
one of these those parties still not clear, but the GDPR document has provisions for
these three levels of you know compensation fines and the penalties. Now the last
days having seeing it is about fifty thousand foot view of the GDP are what the
requirements are if a company now wants to prepare for GDPR compliance what
would be your road map? Simple start is the training and awareness you need to know
the GDPR in details and as I said it's a very simple introduction I am giving to a very
complex subject to understand what is the GDPR privacy protection and security
requirements you need to have some training to understand the requirements in
great detail and then have to create awareness within your company that what is the
new things coming into play. And based on that the next logical step would be to do a
gap assessment or if you want to do little more ahead if you're doing a lot of data
processing then do a data protection impact assessment to understand your situation,
where the gaps are, and what level of risks you are running.
I'm sure you have to update most of your existing privacy rules to be complying with
GDPR and revisit your existing security controls or implement controls so based on the
gaps found out in the gap assessment. You have to roll your new set of policies and
controls zoom to the organization's, and then the last step would be doing some sort
of compliance assessment to make sure that now you are complying with the
GDPR assessment. Now how you want to do that there could be many different ways
you choose to do that, but one common thing, and since it's a European requirement
and the GDPR certifications came kind of alluding towards, and I also like, a
framework so ISO 27001 could be a good framework for any organization to
embrace on. And if you recall the statement and the security they were saying it hast
to have a technical and organizational system and that is where ISO comes into play
that and the fields were not familiar with 27001 for their convenience and just putting
up a diagram here this shows that it 27001 standard it gives a system which helps
you to set up a security manage men system and run it and continuously improve it,
so the left part of the box which talks about the system which you're talking about
setting up the organizational context, setting up the leadership roles and responsibilities.
Then having your operation running following plan-do-check-act Deming cycle and
having a support layer which includes your HR introduced document management
then it provides a set of controls in the form of Annex And you can choose applicable
controls from Annex A which applies to your kind of business operations and
prepare a document which calls a statement of applicability or SOA and ISO also
allows 27001 it says that based on the risk assessment you identify appropriate
controls to mitigate those risks, and those Control Scan be selected from an x-ray
you can write your controls, or you can take controls from any other body of knowledge.
An x-ray of 27001 currently provide one control which talks about data privacy and a
very logical replacement which I'm saying here is if you take the GDPR requirements
that the whole set of GDPR requirements which gets in to you state of your segment
of applicability as a set of your privacy controls, then you have other controls from
Annex A which will ensure your data protection and data security. And the
management system part which is in your left hand side will ensure your continuous
compliance with the requirements which is in the SOA, which is a comprehensive
set of controls including 27001 and GDPR and since 27001 is an international
standard which will be accepted to all of European Union so it will be a logical
first step to show compliance to anyone asking your organization as an evidence
of compliance with the GDPR requirements. So at this time, I like to throw it open
for questions and answers didn't see any questions in the chat box over so if anybody
has any questions, please feel free to ask. Ladies and gentlemen, you can send
questions using the Q&A box located on the lower left of the presentation type
your message in the bottom and click on ask to send it. Sabrata we have questions.
This is a question from Bobby: can you get a copy of the presentation? Yes, Bobby,
we are working on that you can send me an email I can send you a PDF for that.
We are also trying to put it up on your website where you can access this presentation.
I think it's the same question to the next person. There is questioning on is the
GDPR certification voluntary? Yes, it is it is a voluntary certification as per the GDPR
regulation, however, if you are working if you are a processor and working for a
controller, that controller may demand certification from you to show that you are
complying with the GDPR requirements. There's a question for Mark, is that to the
list of the US-based companies will that have a web presence but no offices in Europe?
Well this is a good question mark, if you have a web preference and if you are
collecting personal data from EU Nationals then you are coming into the scheme of
GDPR but we need to go through the list of GDPR requirements to see how
you demonstrate compliance there is not a specific list available till now, or not
that I'm aware of, there could be. The next question is that a US company has to
that I'm aware of, there could be. The next question is that a US company has to
have a DPO located in Europe now if they have a customer there?
It is not saying it is a customer deal, but it says if you have an office there, you
have to designate somebody it is not saying it has to be a DPO but company's
representative available locally to the employees who will act as the DPO or who
to contact in case they have a complaint to lodge. The comer's questions I think
I have already answered it is it is a voluntary but it can be mandatory if you're you
controller you're working with demand for that. There's a question from Loretta
says the companies 27,000 certified and touches PII and adds the field office in
Poland, and that is the impact on my certification audit - what is the impact on
certification audit and what might customers required beyond ISO certification?
So from the scope of 27001 certification as these will have no impact but if you
have to show your customers it compliance to GDPR only for those employees
who are in Poland you have to include the GDPR related the privacy requirements
on GDPR into the scope of your SOA, and you have to be audited against that. So
there's a question, Vincent, where we can find the list of authorized countries I don't
recall them the website but if you go to google we do a search of list of countries
where EU Commission has identified as a having adequate protection that will give
the site or you can write an email to me which is in your chat window I will so I will
find and send you this link. The last question if a company credit card is used
without any direct reference to an individual does this comes under GDPR? That
would be an interesting question because company credit card number is not private
information and according to the very definition of GDPR unless it is attached to an
individual. It is not considered as personal information, so based on my judgment I
would say it is not. The question from Lisa can you elaborate on the transfer of data
versus remotely accessing EU data from another country does remote access where
data is not fully transferred to a country outside EU fall under GDPR? If you are
accessing data remotely then it is not considered as transfer, however, the data
within EU is still covered under GDPR so the body which is storing the data in
the country they are still responsible for managing this safeguarding this data
so if you are a processor you are only accessing the data from here you are
not processing, you are not bringing the data to your facility then we need to
really see about doing a risk assessment do you have any risk of data breach
from your end? If it is proof that there is no chance of data breach, then you
can claim exemption from GDPR. It looks like there is no other question and
we are in the top of the hour there is another question. Will you be able to
the print slides from an email attachment? If you could clarify are you talking
about the slides which I am using in this GDPR a presentation? It will be a PDF
file so you should be able to print that. So I like to thank everyone for taking
time to join this webinar session, and I'm sure it's a very difficult subject and in a
very short amount of time I just try to give you a glimpse of what it is and
what could be effect on your organization definitely I'll encourage everyone to
download the free text copies or seek help from a professional to do an
impact assessment to determine whether your organization will have any impact
based on this current situation. I'll be happy to answer any further questions via
email if you have any questions don't hesitate to shoot me an email and we will
try to put up our presentations available in our website, or I'll be happy to share
individually with any one of you your contacting me. So thank you all have a great
day. This concludes today's DQS Inc. webinar thank you all for attending.
Không có nhận xét nào:
Đăng nhận xét