gdpr european general data protection regulation (gdpr) · 2016-11-14 · european general data...

24
GDPR European General Data Protection Regulation (GDPR)

Upload: others

Post on 21-Feb-2020

11 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

GDPREuropeanGeneralDataProtection

Regulation(GDPR)

Page 2: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

EuropeanGeneralDataProtectionRegulation(GDPR)

WebcastmitSophos– 26.02.2016 2

• „EuropeanDirective“willreplaceall(28)nationaldatasecuritylaws• By2018• 2yearsofgraceperiod• Penaltiesmuchhigher– upto20MillionEUR

Page 3: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

GDPR– TheTimetoActisNow

• Thursday14April2016o EuropeanParliamentapprovesnewrulesfitforthedigitalera

NewProvisions

• Finesupto4%ofannualWWturnover• Arighttobeforgotten• Clearandaffirmativeconsenttotheprocessingof

privatedatabythepersonconcerned• Arighttotransferyourdatatoanotherservice

provider• Therighttoknowwhenyourdatahasbeenhacked• Ensuringthatprivacypoliciesareexplainedinclear

andunderstandablelanguage

Timeline

• Memberstateshave2yearstotransposetheprovisionsofthedirectiveintonationallaw.

• Theregulationwillenterintoforce20daysafteritspublicationintheEUOfficialJournal.

• DuetoUKandIreland’sspecialstatus,thedirective’sprovisionswillonlyapplyinthesecountriestoalimitedextent.

• Denmarkwillbeabletodecidewithin6monthsafterthefinaladoptionofthedirectivewhetheritwantstoimplementitinitsnationallaw.

Page 4: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

TechnicalControl

WebcastmitSophos– 26.02.2016 4

• Dutytousedataprotectionfriendlytechnologyo „Dataprotection by design“

• anddataprotectionfriendlyconfigutrationo „Dataprotectionbydefault“

• TheEUCommissioncandefinerequirementsforspecifictechnicalmeasures

• Itisexpectedthatdetailedsecuritystandardswillbedefinedinthemid-term

Page 5: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

Dutytocommunicatedatabreaches

5

• Shouldapersonaldatabreachoccur,thecompanyisrequiredtonotifythesupervisoryauthoritywithin72hoursafterhavingbecomeawareofthebreach.

Credit CardNumber

Name

Address Salary

Date of Birth

FinancialSituation

TelephoneNumber

IP AddressRFID Tags

Geo Tags

Page 6: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

Encryptionbecomespolitical

Page 7: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

“For many years, we have used encryption to protect our customers’ personal data because we believe it’s the only way to keep their information safe.”Tim Cook, CEO of Apple

Page 8: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

Mac/PCComputer

Phone

Tablet

DataisEverywhere

8

Page 9: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

Mac/PCComputer

HDD

TrueorFalse?FullDiskEncryptionisallyouneed?

9

Page 10: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

FileEncryption

Mac/PCComputer

Cloud-basedFileShare

Servers/SharedFolders

Phone

Tablet

10

Page 11: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

SynchronizedEncryption

EncryptIndividualFiles

11

Page 12: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

SynchronizedEncryption

EncryptIndividualFiles

BYDEFAULT

EVERYWHERE

ALWAYSON

12

Page 13: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

SecureContentCollaborationfortrustedusers

ContentstoredintheCloud

5

Page 14: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

SecureContentCollaborationfortrustedusers

Preventhackersfromaccessingdatastored

intheCloud

ContentsharedviaemailandfromtheCloud

ContentstoredintheCloud

5

Page 15: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

SecureContentCollaborationfortrustedusers

Contentdecryptedforinternaluser

Preventhackersfromaccessingdatastored

intheCloud

ContentsharedviaemailandfromtheCloud

ContentstoredintheCloud

5

Page 16: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

ProductDemo

Page 17: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

17

Page 18: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

18

Page 19: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

Whataboutexternalsharing?

19

Page 20: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“
Page 21: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

21

Page 22: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

22

Page 23: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

Whatyoucandonow

23

• Usethetimelefttopreparecomplianceandstartnow• Analyseallprocesses• Documentsecuritymeasures• DataProtectionfriendlyuseoftechnologiesfromthestart

Page 24: GDPR European General Data Protection Regulation (GDPR) · 2016-11-14 · European General Data Protection Regulation (GDPR) Webcast mit Sophos – 26.02.2016 2 • „European Directive“

24