SlideShare une entreprise Scribd logo
1  sur  52
• Overview Of Privacy & Data Protection (P&DP)
• Current Status on P&DP
• New and updated Privacy Legislations
• Commonalities between legislations
• What is the impact?
• Global P&DP trends
• Q & A
Agenda
Introduction
Before we start…
Check the past webinars on the PECB website at
• https://pecb.com/past-webinars
Find all sessions with Q&A + collaterals (decks, recording) at:
http://ffwd2.me/PECB_ISO27001_webinars (short cut to LinkedIN page)
Previous sessions
After the session, you can find the presentation and recording at
• https://pecb.com/past-webinars
Reference information + Q&A of this session:
https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-2021-compliance-
new-peter-geelen-/
This session collaterals
Overview Of Privacy & Data Protection
(P&DP)
What's in a word…
Data Privacy Definition
Information privacy is the relationship between the collection and dissemination of
data, technology, the public expectation of privacy, and the legal and political
issues surrounding them.*
*https://en.wikipedia.org/wiki/Information_privacy
Data Protection
GDPR Art. 1.1:
"protection of natural persons with regard to the
processing of personal data and rules relating to the
free movement of personal data"
*https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32016R0679
GDPR and privacy
GDPR itself does not mention privacy…
except a footnote on Directive 2002/58/EC, the eCommunications
directive
In GDPR, it's about data protection, which means protecting your
data.
Privacy = "The right to be left alone"
Some Stats – UN Conference on Trade & Development
Privacy, data protection vs. cybersecurity
There is
No Privacy and data protection
Without
Cybersecurity
But you can have cybersecurity without the need of privacy or
data protection.
Privacy & Data Protection vs Enterprise security
In many cases
• Privacy & data protection is targeted to people, persons and
their data
• Privacy & data protection is (mostly) not about company or
enterprise data (finance, operations, products, services…)
BUT
Data breaches of company data do have the same impact (so
treat and protect them equally)
Current Status on P&DP
The battle for your personal data
and privacy
North America - Canada
PIPEDA - Personal Information Protection and Electronic Documents Act
• Federal Legislation managed by the Office of the Privacy Commissioner of Canada
• An individual’s consent must be obtained for the collection, use or disclosure of their personal
information; individuals have the right to access their personal information and to challenge
any inaccuracies in it.
• Personal information can inly be used for the purposes for which it was collected otherwise
consent must be obtained again.
• Personal information must be appropriately protected.
• Applies to private sector organizations in Canada.
• Is supplemented by privacy laws at the Provincial level in Canada (e.g., laws in Ontario versus
Quebec, etc.).
• Data that crosses borders, whether within Canada or internationally, is a concern.
• Fines: up to $100,000 CAD
North America - Canada
Other laws:
• CASL – Canada Anti Spam Legislation
• Federal law
• Requires individual’s expressed or implied consent, depending
upon the situation
• Requires unsubscribe mechanism
• Up to $1 million CAD fine per violation and up to $10 million CAD
fine for corporations
Each Province/Territory in Canada, has its own privacy and health data
protection laws but each aligns with PIPEDA and then augments
PIPEDA with regional guidance.
North America - Canada
Multiple laws and legislations across Canada at the Provincial
level.
North America - Canada
Advice:
• Become familiar with both the Federal and Provincial
laws and legislations before you assume that you are
managing personal data correctly
Important: better apply this to any privacy & data
protection implementation, not only to USA/CA region.
North America - USA
E-Sign – Electronic Signatures in Global and National
Commerce Act
• Describes and validates electronic forms of data including e-
signatures
HIPAA – Health Insurance Portability and Accountability Act of
1996
• Protects privacy of personal health information
• Carries penalties of from $100 USD to $50,000 USD per record
violation
North America - USA
California Consumer Privacy Act
• Applies to any organization that does business in California and which has
gross revenues in excess of $25 million USD or that has 50,000 or more
personal records or that earns ½+ of its revenue from selling personal
information
• Penalties of from $2,500 to $7,500 USD per violation
NY Shield Act
• If you hold any personal or private data of any New York resident, this applies
to you
• Penalties of $5,000 USD or $20 USD per violation up to $250,000 USD
Maximum
Central and South America
Mexico - Federal Law on Personal Data Held by Private Parties (FLPPDPP)
• Applies to private sector
• Oddly, no need to inform any government body should a breach occur
Chile- Law No. 19.628 on the Protection of Private Life 1999
• Under development but will align with international privacy laws and standards
Brazil – Law No. 13.709 – General Personal Data Protection Law
• Into effect in September 2020 but will be enforced beginning August 2021
• Similar to GDPR with DPO’s required, data breach and transfer requirements, and privacy
impact assessments
• Established history of enforcement WRT privacy
Other Countries in Central and South America have currently implemented, draft or in progress
privacy laws with only a few countries/locations in Central & South America and the Caribbean with
no privacy laws (oddly, Puerto Rico has none).
Europe
Type of law (Source: EC)
• Regulation
• Regulations are legal acts that apply automatically and uniformly to all EU
countries as soon as they enter into force,
• without needing to be transposed into national law.
• They are binding in their entirety on all EU countries.
• Directive
• Directives require EU countries to achieve a certain result, but leave them
free to choose how to do so. EU countries must adopt measures to
incorporate them into national law (transpose) in order to achieve the
objectives set by the directive.
Europe
GDPR
• Data protection (not privacy)
• Regulation
• Tuned with national legislation
Europe
Other legislation that impact privacy & data protection
• eCommunications & eCommerce
• ePrivacy directive (in review/update)
But also
• NIS (cybersecurity for public & critical infrastructure)
• NIS v2 coming up
• CyberAct
New and updated Privacy Legislations
Keep an eye on…
North America - Canada
CCPA – Consumer Privacy Protection Act
• Enhancement to PIPEDA
• Privacy and Data Protection Tribunal is established.
• Same acronym as the California Consumer Protection Act (also, CCPA) but
aims to be even stronger.
• Organizations must maintain a privacy management program; meaningful
consent must be obtained; deidentified data is covered; right to erasure;
enhanced enforcement.
• Private lawsuits for violations are permitted.
• Third-party service providers are in scope.
• Penalties for non-compliance: up to 3% of global revenue or $10 million CAD
OR up to 5% of global revenue or $25 million CAD for serious breaches.
Europe
GDPR Processing principles
• eCommunications & eCommerce
• High impact on direct marketing
• ePrivacy directive (in review/update)
• Aligned with GDPR
• High impact on direct marketing
• NIS (cybersecurity for public & critical infrastructure)
• NIS v2 coming up
• CyberAct (Cyber certification, PPT, …)
Commonalities between legislations
Comparing and understanding the context of
the legislations
Some Common Features
• Privacy officer : Like the GDPR requirement, many privacy laws across the world are
looking to have a personal appointed in your organization who is accountable for
privacy.
• Penalties : As we have seen with GDPR and with HIPAA in the USA, financial
penalties for violations of privacy legislation or even for improper breach handling can
be costly both in terms of monetary cost as well as reputational impact.
• Privacy Program : Privacy legislations are increasingly looking for organizations to
have a privacy program in place (e.g., privacy policy(ies), breach management plan,
privacy awareness training for staff, etc.).
• Breach Management and Notification : It is critical to have a documented data
breach management plan that also includes a breach notification process.
• Consent : Consent for the collection of personal data that includes a precise
description of the planned use for the data is critical.
• Note that many privacy or data protection laws include the publishing of data breaches
or infractions of the privacy legislation. (“Name and Shame”)
North America - Canada
CCPA – Consumer Privacy Protection Act
• Enhancement to PIPEDA
• Privacy and Data Protection Tribunal is established.
• Same acronym as the California Consumer Protection Act (also, CCPA) but
aims to be even stronger.
• Organizations must maintain a privacy management program; meaningful
consent must be obtained; deidentified data is covered; right to erasure;
enhanced enforcement.
• Private lawsuits for violations are permitted.
• Third-party service providers are in scope.
• Penalties for non-compliance: up to 3% of global revenue or $10 million CAD
OR up to 5% of global revenue or $25 million CAD for serious breaches.
Europe
GDPR Processing principles
• Principles (Art. 5) (lawful, fairly, transparent, …)
• Lawfulness of processing Art. 6
consent,
Contract,
legal oblication,
vital interest,
public interest,
legitimate interest
Europe
GDPR Subject Rights
• Conditions for consent (incl. minors/children)
• Special categories of data
• Rights
Right of access
Right to rectification
Right to be forgotten
Right to restrict processing
Right to notification
Right to data portability
Right to object
Europe
GDPR Obligations - Data controllers & data processors
• Data protection by default
• Data protection by design
• Joint controllers
• Record of processing (processing register)
• Data breach management (incl. notifications)
• Security of processing
• DPIA
Europe
GDPR Obligations - Data controllers & data processors
• DPO (data protection officer)
Designation (public authoriticy, large scale, sensitive data)
Position (independent, advisory, …)
Tasks
Inform & advice
Monitor compliance
Cooperate with DPA
SoD: NOT responsible/accountable for DC/DP tasks
Europe
GDPR Fines
• Purpose: in each individual case , to be
effective,
proportionate and
dissuasive
• Depending the nature, gravity and duration of the infringement
infringement
2% or €10M
4% or €20M
What is the impact?
Europe
Data protection authorities in action… a trend.
There are various sites that follow up on the GDPR fines
For example:
• https://www.enforcementtracker.com/
• https://www.coreview.com/blog/alpin-gdpr-fines-list/
• https://www.privacyaffairs.com/gdpr-fines/
• …
In general
• Powerful subject
• Data controllers balancing between
• Subject rights
• Government
• Commercial interest
• Cross border impact of legislation
GDPR is not only for EU companies or EU citizens
P&DP new trends
Privacy & Data protection is HOT
• Driver: Cybercrime/breach impact grows
• Commercial impact vs subjects
• Existing Social media platforms have difficulties to find the
new way of working aligned with regulations
• New platforms don't get it always right
• Take back privacy
Very low level of protection of internet data
Free flow of data, now issue…
Privacy & Data protection is HOT
• Cookies management
• Dark patterns ("Accept All", before you find the "configure button")
• Cookie psychology
• Direct marketing
Data brokers position
Collection of data vs obligations of transparency
Public data vs purpose definitions
• Cross border, international impact
Data brokers out of reach
Privacy & Data protection is HOT
And also…
• IoT Security impact on P&DP
• Camera's
• Cars
• Toys
• …
References
Interesting information sources
Reference material
Collateral references and additional info posted on
• https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-
2021-compliance-new-peter-geelen-/
ISO/IEC 27701
Training Courses
• ISO/IEC 27701 Foundation
2 Day Course
• ISO/IEC 27701 Lead Implementer
5Days Course
Exam and certification fees are included in the training price.
https://pecb.com/en/education-and-certification-for-individuals/iso-
27701
www.pecb.com/events
Appendix
Ramping up…
Relevant PECB Training courses
Relevant Training
PIMS
• PECB ISO 27701 Foundation
• PECB ISO 27701 LI
• PECB ISO 27701 LA
Information Security
• PECB ISO 27001 LI
• PECB ISO 27001 LA
• PECB ISO 27002 LM
Relevant Training
Data protection
• PECB Certified Data protection Officer (GDPR)
Privacy
• PECB ISO29100 LI
Other Relevant Training
Incident Management
• PECB ISO 27035 LI
Risk Management
• PECB ISO 27005 LI
Check the PECB agenda, select the ISO/IEC 27701 Lead
Implementer
https://pecb.com/en/partnerEvent/event_schedule_list
Training Events
For full detailed information about an event click on the ‘View’ button on the right hand
side under ‘View full details’.
Note: Before applying for any training courses listed below, please make sure you are
registered to PECB
Training Agenda
THANK YOU
?
info@cyberminute.com CyberMinute
asenglish@hotmail.com BOT Security Solutions

Contenu connexe

Tendances

Enabling Data Governance - Data Trust, Data Ethics, Data Quality
Enabling Data Governance - Data Trust, Data Ethics, Data QualityEnabling Data Governance - Data Trust, Data Ethics, Data Quality
Enabling Data Governance - Data Trust, Data Ethics, Data QualityEryk Budi Pratama
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)Kimberly Simon MBA
 
Information Security
Information SecurityInformation Security
Information Securitychenpingling
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protectionsp_krishna
 
Human resources security
Human resources securityHuman resources security
Human resources securityCAS
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentationPriyanka Aash
 
Privacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationPrivacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationEryk Budi Pratama
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Introduction to the management of information security
Introduction to the management of information security  Introduction to the management of information security
Introduction to the management of information security Sammer Qader
 
Data Loss Prevention (DLP) - Fundamental Concept - Eryk
Data Loss Prevention (DLP) - Fundamental Concept - ErykData Loss Prevention (DLP) - Fundamental Concept - Eryk
Data Loss Prevention (DLP) - Fundamental Concept - ErykEryk Budi Pratama
 
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...Eryk Budi Pratama
 
Personal Data Protection in Indonesia
Personal Data Protection in IndonesiaPersonal Data Protection in Indonesia
Personal Data Protection in IndonesiaEryk Budi Pratama
 
CISSP Prep: Ch 1: Security Governance Through Principles and Policies
CISSP Prep: Ch 1: Security Governance Through Principles and PoliciesCISSP Prep: Ch 1: Security Governance Through Principles and Policies
CISSP Prep: Ch 1: Security Governance Through Principles and PoliciesSam Bowne
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
ISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowPECB
 
Nist cybersecurity framework isc2 quantico
Nist cybersecurity framework  isc2 quanticoNist cybersecurity framework  isc2 quantico
Nist cybersecurity framework isc2 quanticoTuan Phan
 

Tendances (20)

Enabling Data Governance - Data Trust, Data Ethics, Data Quality
Enabling Data Governance - Data Trust, Data Ethics, Data QualityEnabling Data Governance - Data Trust, Data Ethics, Data Quality
Enabling Data Governance - Data Trust, Data Ethics, Data Quality
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)
 
Information Security
Information SecurityInformation Security
Information Security
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Privacy & Data Protection
Privacy & Data ProtectionPrivacy & Data Protection
Privacy & Data Protection
 
Human resources security
Human resources securityHuman resources security
Human resources security
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
Privacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationPrivacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program Implementation
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Introduction to the management of information security
Introduction to the management of information security  Introduction to the management of information security
Introduction to the management of information security
 
Data protection
Data protectionData protection
Data protection
 
Data Loss Prevention (DLP) - Fundamental Concept - Eryk
Data Loss Prevention (DLP) - Fundamental Concept - ErykData Loss Prevention (DLP) - Fundamental Concept - Eryk
Data Loss Prevention (DLP) - Fundamental Concept - Eryk
 
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...
Implikasi UU PDP terhadap Tata Kelola Data Sektor Kesehatan - Rangkuman UU Pe...
 
Personal Data Protection in Indonesia
Personal Data Protection in IndonesiaPersonal Data Protection in Indonesia
Personal Data Protection in Indonesia
 
CISSP Prep: Ch 1: Security Governance Through Principles and Policies
CISSP Prep: Ch 1: Security Governance Through Principles and PoliciesCISSP Prep: Ch 1: Security Governance Through Principles and Policies
CISSP Prep: Ch 1: Security Governance Through Principles and Policies
 
NIST Cybersecurity Framework 101
NIST Cybersecurity Framework 101  NIST Cybersecurity Framework 101
NIST Cybersecurity Framework 101
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
ISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to know
 
Nist cybersecurity framework isc2 quantico
Nist cybersecurity framework  isc2 quanticoNist cybersecurity framework  isc2 quantico
Nist cybersecurity framework isc2 quantico
 

Similaire à Data Privacy Trends in 2021: Compliance with New Regulations

Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Financial Poise
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsFinancial Poise
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analyticsshekharkanodia
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Financial Poise
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Diana Maier
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance Dovetail Software
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowOgilvy Health
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRCase IQ
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberRachel Aldighieri
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014Rachel Aldighieri
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issuesStefan Schippers
 
Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Jason Haislmaier
 

Similaire à Data Privacy Trends in 2021: Compliance with New Regulations (20)

Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analytics
 
Cloud primer
Cloud primerCloud primer
Cloud primer
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to know
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
The Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPRThe Countdown is on: Key Things to Know About the GDPR
The Countdown is on: Key Things to Know About the GDPR
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
Legal update Leeds - 7 October 2014
Legal update Leeds -  7 October 2014Legal update Leeds -  7 October 2014
Legal update Leeds - 7 October 2014
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 
Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)Crash Course on Data Privacy (December 2012)
Crash Course on Data Privacy (December 2012)
 

Plus de PECB

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityPECB
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernancePECB
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...PECB
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...PECB
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyPECB
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...PECB
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationPECB
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsPECB
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?PECB
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...PECB
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC PECB
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...PECB
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...PECB
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA PECB
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?PECB
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptxPECB
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxPECB
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023PECB
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemPECB
 

Plus de PECB (20)

DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of CybersecurityDORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
DORA, ISO/IEC 27005, and the Rise of AI: Securing the Future of Cybersecurity
 
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI GovernanceSecuring the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
Securing the Future: ISO/IEC 27001, ISO/IEC 42001, and AI Governance
 
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
ISO/IEC 27032, ISO/IEC 27002, and CMMC Frameworks - Achieving Cybersecurity M...
 
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
ISO/IEC 27001 and ISO/IEC 27035: Building a Resilient Cybersecurity Strategy ...
 
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks EffectivelyISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
ISO/IEC 27001 and ISO/IEC 27005: Managing AI Risks Effectively
 
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
Aligning ISO/IEC 27032:2023 and ISO/IEC 27701: Strengthening Cybersecurity Re...
 
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital TransformationISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
ISO/IEC 27001 and ISO/IEC 27032:2023 - Safeguarding Your Digital Transformation
 
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulationsManaging ISO 31000 Framework in AI Systems - The EU ACT and other regulations
Managing ISO 31000 Framework in AI Systems - The EU ACT and other regulations
 
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
Impact of Generative AI in Cybersecurity - How can ISO/IEC 27032 help?
 
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
GDPR and Data Protection: Ensure compliance and minimize the risk of penaltie...
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Student Information Session University KTMC
Student Information Session University KTMC Student Information Session University KTMC
Student Information Session University KTMC
 
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
ISO/IEC 27001 and ISO 22301 - How to ensure business survival against cyber a...
 
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
Integrating ISO/IEC 27001 and ISO 31000 for Effective Information Security an...
 
Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA Student Information Session University CREST ADVISORY AFRICA
Student Information Session University CREST ADVISORY AFRICA
 
IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?IT Governance and Information Security – How do they map?
IT Governance and Information Security – How do they map?
 
Information Session University Egybyte.pptx
Information Session University Egybyte.pptxInformation Session University Egybyte.pptx
Information Session University Egybyte.pptx
 
Student Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptxStudent Information Session University Digital Encode.pptx
Student Information Session University Digital Encode.pptx
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
ISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management systemISO 28000:2022 – Reduce risks and improve the security management system
ISO 28000:2022 – Reduce risks and improve the security management system
 

Dernier

Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxQ4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxlancelewisportillo
 
Concurrency Control in Database Management system
Concurrency Control in Database Management systemConcurrency Control in Database Management system
Concurrency Control in Database Management systemChristalin Nelson
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptxmary850239
 
Activity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationActivity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationRosabel UA
 
Dust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSEDust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSEaurabinda banchhor
 
Presentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptxPresentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptxRosabel UA
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 
Oppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmOppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmStan Meyer
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Mark Reed
 
Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...Seán Kennedy
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)lakshayb543
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Projectjordimapav
 
Expanded definition: technical and operational
Expanded definition: technical and operationalExpanded definition: technical and operational
Expanded definition: technical and operationalssuser3e220a
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSJoshuaGantuangco2
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptxmary850239
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Celine George
 
Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4JOYLYNSAMANIEGO
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...Postal Advocate Inc.
 

Dernier (20)

Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptxQ4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
Q4-PPT-Music9_Lesson-1-Romantic-Opera.pptx
 
Concurrency Control in Database Management system
Concurrency Control in Database Management systemConcurrency Control in Database Management system
Concurrency Control in Database Management system
 
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptxLEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx
 
Activity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translationActivity 2-unit 2-update 2024. English translation
Activity 2-unit 2-update 2024. English translation
 
Dust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSEDust Of Snow By Robert Frost Class-X English CBSE
Dust Of Snow By Robert Frost Class-X English CBSE
 
Presentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptxPresentation Activity 2. Unit 3 transv.pptx
Presentation Activity 2. Unit 3 transv.pptx
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 
Oppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and FilmOppenheimer Film Discussion for Philosophy and Film
Oppenheimer Film Discussion for Philosophy and Film
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)
 
Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...Student Profile Sample - We help schools to connect the data they have, with ...
Student Profile Sample - We help schools to connect the data they have, with ...
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Project
 
Expanded definition: technical and operational
Expanded definition: technical and operationalExpanded definition: technical and operational
Expanded definition: technical and operational
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
 
Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4Daily Lesson Plan in Mathematics Quarter 4
Daily Lesson Plan in Mathematics Quarter 4
 
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptxYOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
YOUVE GOT EMAIL_FINALS_EL_DORADO_2024.pptx
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
 

Data Privacy Trends in 2021: Compliance with New Regulations

  • 1.
  • 2. • Overview Of Privacy & Data Protection (P&DP) • Current Status on P&DP • New and updated Privacy Legislations • Commonalities between legislations • What is the impact? • Global P&DP trends • Q & A Agenda
  • 5. Check the past webinars on the PECB website at • https://pecb.com/past-webinars Find all sessions with Q&A + collaterals (decks, recording) at: http://ffwd2.me/PECB_ISO27001_webinars (short cut to LinkedIN page) Previous sessions
  • 6. After the session, you can find the presentation and recording at • https://pecb.com/past-webinars Reference information + Q&A of this session: https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-2021-compliance- new-peter-geelen-/ This session collaterals
  • 7. Overview Of Privacy & Data Protection (P&DP) What's in a word…
  • 8. Data Privacy Definition Information privacy is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, and the legal and political issues surrounding them.* *https://en.wikipedia.org/wiki/Information_privacy
  • 9. Data Protection GDPR Art. 1.1: "protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data" *https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32016R0679
  • 10. GDPR and privacy GDPR itself does not mention privacy… except a footnote on Directive 2002/58/EC, the eCommunications directive In GDPR, it's about data protection, which means protecting your data. Privacy = "The right to be left alone"
  • 11. Some Stats – UN Conference on Trade & Development
  • 12. Privacy, data protection vs. cybersecurity There is No Privacy and data protection Without Cybersecurity But you can have cybersecurity without the need of privacy or data protection.
  • 13. Privacy & Data Protection vs Enterprise security In many cases • Privacy & data protection is targeted to people, persons and their data • Privacy & data protection is (mostly) not about company or enterprise data (finance, operations, products, services…) BUT Data breaches of company data do have the same impact (so treat and protect them equally)
  • 14. Current Status on P&DP The battle for your personal data and privacy
  • 15. North America - Canada PIPEDA - Personal Information Protection and Electronic Documents Act • Federal Legislation managed by the Office of the Privacy Commissioner of Canada • An individual’s consent must be obtained for the collection, use or disclosure of their personal information; individuals have the right to access their personal information and to challenge any inaccuracies in it. • Personal information can inly be used for the purposes for which it was collected otherwise consent must be obtained again. • Personal information must be appropriately protected. • Applies to private sector organizations in Canada. • Is supplemented by privacy laws at the Provincial level in Canada (e.g., laws in Ontario versus Quebec, etc.). • Data that crosses borders, whether within Canada or internationally, is a concern. • Fines: up to $100,000 CAD
  • 16. North America - Canada Other laws: • CASL – Canada Anti Spam Legislation • Federal law • Requires individual’s expressed or implied consent, depending upon the situation • Requires unsubscribe mechanism • Up to $1 million CAD fine per violation and up to $10 million CAD fine for corporations Each Province/Territory in Canada, has its own privacy and health data protection laws but each aligns with PIPEDA and then augments PIPEDA with regional guidance.
  • 17. North America - Canada Multiple laws and legislations across Canada at the Provincial level.
  • 18. North America - Canada Advice: • Become familiar with both the Federal and Provincial laws and legislations before you assume that you are managing personal data correctly Important: better apply this to any privacy & data protection implementation, not only to USA/CA region.
  • 19. North America - USA E-Sign – Electronic Signatures in Global and National Commerce Act • Describes and validates electronic forms of data including e- signatures HIPAA – Health Insurance Portability and Accountability Act of 1996 • Protects privacy of personal health information • Carries penalties of from $100 USD to $50,000 USD per record violation
  • 20. North America - USA California Consumer Privacy Act • Applies to any organization that does business in California and which has gross revenues in excess of $25 million USD or that has 50,000 or more personal records or that earns ½+ of its revenue from selling personal information • Penalties of from $2,500 to $7,500 USD per violation NY Shield Act • If you hold any personal or private data of any New York resident, this applies to you • Penalties of $5,000 USD or $20 USD per violation up to $250,000 USD Maximum
  • 21. Central and South America Mexico - Federal Law on Personal Data Held by Private Parties (FLPPDPP) • Applies to private sector • Oddly, no need to inform any government body should a breach occur Chile- Law No. 19.628 on the Protection of Private Life 1999 • Under development but will align with international privacy laws and standards Brazil – Law No. 13.709 – General Personal Data Protection Law • Into effect in September 2020 but will be enforced beginning August 2021 • Similar to GDPR with DPO’s required, data breach and transfer requirements, and privacy impact assessments • Established history of enforcement WRT privacy Other Countries in Central and South America have currently implemented, draft or in progress privacy laws with only a few countries/locations in Central & South America and the Caribbean with no privacy laws (oddly, Puerto Rico has none).
  • 22. Europe Type of law (Source: EC) • Regulation • Regulations are legal acts that apply automatically and uniformly to all EU countries as soon as they enter into force, • without needing to be transposed into national law. • They are binding in their entirety on all EU countries. • Directive • Directives require EU countries to achieve a certain result, but leave them free to choose how to do so. EU countries must adopt measures to incorporate them into national law (transpose) in order to achieve the objectives set by the directive.
  • 23. Europe GDPR • Data protection (not privacy) • Regulation • Tuned with national legislation
  • 24. Europe Other legislation that impact privacy & data protection • eCommunications & eCommerce • ePrivacy directive (in review/update) But also • NIS (cybersecurity for public & critical infrastructure) • NIS v2 coming up • CyberAct
  • 25. New and updated Privacy Legislations Keep an eye on…
  • 26. North America - Canada CCPA – Consumer Privacy Protection Act • Enhancement to PIPEDA • Privacy and Data Protection Tribunal is established. • Same acronym as the California Consumer Protection Act (also, CCPA) but aims to be even stronger. • Organizations must maintain a privacy management program; meaningful consent must be obtained; deidentified data is covered; right to erasure; enhanced enforcement. • Private lawsuits for violations are permitted. • Third-party service providers are in scope. • Penalties for non-compliance: up to 3% of global revenue or $10 million CAD OR up to 5% of global revenue or $25 million CAD for serious breaches.
  • 27. Europe GDPR Processing principles • eCommunications & eCommerce • High impact on direct marketing • ePrivacy directive (in review/update) • Aligned with GDPR • High impact on direct marketing • NIS (cybersecurity for public & critical infrastructure) • NIS v2 coming up • CyberAct (Cyber certification, PPT, …)
  • 28. Commonalities between legislations Comparing and understanding the context of the legislations
  • 29. Some Common Features • Privacy officer : Like the GDPR requirement, many privacy laws across the world are looking to have a personal appointed in your organization who is accountable for privacy. • Penalties : As we have seen with GDPR and with HIPAA in the USA, financial penalties for violations of privacy legislation or even for improper breach handling can be costly both in terms of monetary cost as well as reputational impact. • Privacy Program : Privacy legislations are increasingly looking for organizations to have a privacy program in place (e.g., privacy policy(ies), breach management plan, privacy awareness training for staff, etc.). • Breach Management and Notification : It is critical to have a documented data breach management plan that also includes a breach notification process. • Consent : Consent for the collection of personal data that includes a precise description of the planned use for the data is critical. • Note that many privacy or data protection laws include the publishing of data breaches or infractions of the privacy legislation. (“Name and Shame”)
  • 30. North America - Canada CCPA – Consumer Privacy Protection Act • Enhancement to PIPEDA • Privacy and Data Protection Tribunal is established. • Same acronym as the California Consumer Protection Act (also, CCPA) but aims to be even stronger. • Organizations must maintain a privacy management program; meaningful consent must be obtained; deidentified data is covered; right to erasure; enhanced enforcement. • Private lawsuits for violations are permitted. • Third-party service providers are in scope. • Penalties for non-compliance: up to 3% of global revenue or $10 million CAD OR up to 5% of global revenue or $25 million CAD for serious breaches.
  • 31. Europe GDPR Processing principles • Principles (Art. 5) (lawful, fairly, transparent, …) • Lawfulness of processing Art. 6 consent, Contract, legal oblication, vital interest, public interest, legitimate interest
  • 32. Europe GDPR Subject Rights • Conditions for consent (incl. minors/children) • Special categories of data • Rights Right of access Right to rectification Right to be forgotten Right to restrict processing Right to notification Right to data portability Right to object
  • 33. Europe GDPR Obligations - Data controllers & data processors • Data protection by default • Data protection by design • Joint controllers • Record of processing (processing register) • Data breach management (incl. notifications) • Security of processing • DPIA
  • 34. Europe GDPR Obligations - Data controllers & data processors • DPO (data protection officer) Designation (public authoriticy, large scale, sensitive data) Position (independent, advisory, …) Tasks Inform & advice Monitor compliance Cooperate with DPA SoD: NOT responsible/accountable for DC/DP tasks
  • 35. Europe GDPR Fines • Purpose: in each individual case , to be effective, proportionate and dissuasive • Depending the nature, gravity and duration of the infringement infringement 2% or €10M 4% or €20M
  • 36. What is the impact?
  • 37. Europe Data protection authorities in action… a trend. There are various sites that follow up on the GDPR fines For example: • https://www.enforcementtracker.com/ • https://www.coreview.com/blog/alpin-gdpr-fines-list/ • https://www.privacyaffairs.com/gdpr-fines/ • …
  • 38. In general • Powerful subject • Data controllers balancing between • Subject rights • Government • Commercial interest • Cross border impact of legislation GDPR is not only for EU companies or EU citizens
  • 40. Privacy & Data protection is HOT • Driver: Cybercrime/breach impact grows • Commercial impact vs subjects • Existing Social media platforms have difficulties to find the new way of working aligned with regulations • New platforms don't get it always right • Take back privacy Very low level of protection of internet data Free flow of data, now issue…
  • 41. Privacy & Data protection is HOT • Cookies management • Dark patterns ("Accept All", before you find the "configure button") • Cookie psychology • Direct marketing Data brokers position Collection of data vs obligations of transparency Public data vs purpose definitions • Cross border, international impact Data brokers out of reach
  • 42. Privacy & Data protection is HOT And also… • IoT Security impact on P&DP • Camera's • Cars • Toys • …
  • 44. Reference material Collateral references and additional info posted on • https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends- 2021-compliance-new-peter-geelen-/
  • 45. ISO/IEC 27701 Training Courses • ISO/IEC 27701 Foundation 2 Day Course • ISO/IEC 27701 Lead Implementer 5Days Course Exam and certification fees are included in the training price. https://pecb.com/en/education-and-certification-for-individuals/iso- 27701 www.pecb.com/events
  • 47. Ramping up… Relevant PECB Training courses
  • 48. Relevant Training PIMS • PECB ISO 27701 Foundation • PECB ISO 27701 LI • PECB ISO 27701 LA Information Security • PECB ISO 27001 LI • PECB ISO 27001 LA • PECB ISO 27002 LM
  • 49. Relevant Training Data protection • PECB Certified Data protection Officer (GDPR) Privacy • PECB ISO29100 LI
  • 50. Other Relevant Training Incident Management • PECB ISO 27035 LI Risk Management • PECB ISO 27005 LI
  • 51. Check the PECB agenda, select the ISO/IEC 27701 Lead Implementer https://pecb.com/en/partnerEvent/event_schedule_list Training Events For full detailed information about an event click on the ‘View’ button on the right hand side under ‘View full details’. Note: Before applying for any training courses listed below, please make sure you are registered to PECB Training Agenda

Notes de l'éditeur

  1. Peter
  2. Peter
  3. Check the past webinars on the PECB website at https://pecb.com/past-webinars Find all sessions with Q&A + collaterals (decks, recording) at: http://ffwd2.me/PECB_ISO27001_webinars (short cut to LinkedIN page)
  4. After the session, you can find the presentation and recording at https://pecb.com/past-webinars Reference information + Q&A of this session: https://www.linkedin.com/pulse/pecb-webinar-data-privacy-trends-2021-compliance-new-peter-geelen-/
  5. Tony
  6. Tony
  7. Peter
  8. Peter
  9. Tony https://unctad.org/page/data-protection-and-privacy-legislation-worldwide
  10. Pete
  11. Peter
  12. https://ec.europa.eu/info/law/law-making-process/types-eu-law_en
  13. https://ec.europa.eu/commission/presscorner/detail/en/QANDA_19_3369 Cyberact: https://ec.europa.eu/digital-single-market/en/news/eu-cybersecurity-act-glance bit.ly/EUCyberAct
  14. Peter
  15. https://ec.europa.eu/info/law/law-making-process/types-eu-law_en
  16. Peter
  17. Peter