Europrivacy Introduction – Your Gateway to Certified GDPR Compliance

IT Governance Ltd
27 Sept 202349:49

Summary

TLDRAlan Calder, founder of IT Governance, introduces a webinar on EuroPrivacy certification as a gateway to GDPR compliance. He highlights the importance of GDPR, the role of EuroPrivacy certification in ensuring compliance, and offers practical advice on achieving certification. The webinar covers key principles, benefits, and practical steps towards GDPR compliance, with a Q&A session addressing various related queries.

Takeaways

  • 😀 Alan Calder, the founder of I.T. Governance, hosted the webinar focusing on Europe's privacy and GDPR compliance.
  • 📚 I.T. Governance is a global leader in GDPR and has served over 12,000 clients across five continents, emphasizing their experience in the field.
  • 🌐 Europe Privacy Certification is the first certification mechanism recognized by the European Data Protection Board, demonstrating compliance with GDPR.
  • 📜 The certification is valid for three years and covers all core areas of GDPR, including data processing, protection, and the rights of data subjects.
  • 🔒 The certification is particularly relevant for organizations required to appoint a Data Protection Officer (DPO) and is recognized in all 27 EU member states.
  • 🏢 Organizations seeking certification must meet core criteria, including lawful data processing, respecting individual rights, and ensuring data security.
  • 🔑 Benefits of Europe Privacy Certification include demonstrating legal compliance, building trust with customers, and reducing the risk of non-compliance fines.
  • 🛡️ GDPR and cybersecurity are closely linked, with GDPR emphasizing the need for robust security measures to protect personal data.
  • 🔄 The certification process involves a gap analysis, updating data flow mapping, staff training, and ensuring processes are in line with GDPR principles.
  • 🔑 Euro Privacy Certification complements other standards like ISO 27001, providing an additional layer of assurance for data protection and compliance.
  • 💻 Tools like Cyber Comply can simplify GDPR compliance and are instrumental in achieving Europe Privacy Certification by automating various compliance processes.

Q & A

  • What is the main focus of the webinar presented by Alan Calder?

    -The main focus of the webinar is Europe's privacy and the introduction to certified GDPR compliance, specifically discussing the Euro Privacy certification mechanism.

  • Who is the host of the webinar and what is his background?

    -Alan Calder is the host of the webinar. He is the founder of I.T. Governance, part of the ERC International Group, and has been involved in cybersecurity and privacy for 25 years. He has written several books on GDPR and cybersecurity.

  • What is the significance of Euro Privacy certification in terms of GDPR compliance?

    -Euro Privacy certification is significant as it is the first certification mechanism recognized by the European Data Protection Board, providing a way for organizations to demonstrate their GDPR compliance.

  • How does the Euro Privacy certification benefit organizations in terms of data protection?

    -The Euro Privacy certification benefits organizations by demonstrating legal compliance, improving trust with customers and partners, reducing the risk of non-compliance fines, and providing a competitive advantage.

  • What are the core criteria that organizations need to meet to achieve Euro Privacy certification?

    -The core criteria for Euro Privacy certification cover aspects of data processing and protection, including lawfulness of data processing, data subject rights, security of processing, data protection by design, and compliance with GDPR requirements.

  • What is the role of a Data Protection Officer (DPO) in the context of Euro Privacy certification?

    -A DPO plays a crucial role in ensuring that an organization's data processing activities comply with GDPR and the requirements of Euro Privacy certification, especially since the certification is currently available only to organizations required to appoint a DPO.

  • How does Euro Privacy certification simplify the process of demonstrating GDPR compliance to stakeholders?

    -Euro Privacy certification simplifies the demonstration of GDPR compliance by providing a single, recognized certificate that can be presented to stakeholders, clients, regulators, and partners, eliminating the need for complex explanations or assurances.

  • What is the relationship between ISO 27001 and Euro Privacy certification?

    -ISO 27001 certification can serve as a fundamental building block for Euro Privacy certification, as it demonstrates a compliance data protection regime. Organizations with ISO 27001 certification can build upon this to achieve Euro Privacy certification.

  • How does the Euro Privacy certification help with international data transfers?

    -Euro Privacy certification helps with international data transfers by ensuring that organizations have mechanisms in place to comply with GDPR requirements for transferring personal data to third countries or international organizations.

  • What steps should an organization take to start their GDPR compliance journey towards Euro Privacy certification?

    -An organization should start with a gap analysis to identify the difference between their current GDPR compliance activities and the requirements of Euro Privacy certification. They should then create an implementation plan, update data flow mapping, ensure staff competence and awareness, modify processes as necessary, and carry out penetration testing.

  • What is the duration of a Euro Privacy certification and what happens during this period?

    -A Euro Privacy certification is valid for three years, during which there are surveillance visits to ensure ongoing compliance. At the end of the three-year period, there is a recertification process.

Outlines

00:00

🌐 Introduction to GDPR Compliance Webinar

The webinar, hosted by Alan Calder, founder of I.T. Governance, commences with an introduction to the company's expertise in cybersecurity, privacy, and GDPR. Alan highlights I.T. Governance's global presence, client base, and partnership with Euro privacy. The session aims to guide attendees on GDPR compliance, emphasizing the importance of the mute function for a clear broadcast and the use of the webinar's question feature for future engagement.

05:01

📜 The Emergence and Impact of Euro Privacy Certification

This paragraph delves into the inception of Euro privacy certification, established as a response to the need for demonstrable GDPR compliance. Euro privacy, recognized across the EU, offers a simplified approach to proving compliance, beneficial for interactions with clients, regulators, and stakeholders. The certification is applicable to organizations required to appoint a Data Protection Officer (DPO) and covers all aspects of GDPR, including data processing, security, and the rights of data subjects.

10:03

🛡️ Benefits and Principles of Euro Privacy Certification

The benefits of Euro privacy certification are underscored, including legal compliance demonstration, trust improvement with customers and partners, and a competitive advantage in the market. The certification also mitigates the risk of non-compliance fines and legal issues. Key principles include lawful data processing, upholding data subjects' rights, and ensuring data controller and processor responsibilities are met, alongside robust security measures and data protection by design.

15:03

🔄 Transitioning to Euro Privacy Certification

The process of transitioning to Euro privacy certification is outlined, beginning with a gap analysis to identify the difference between current GDPR compliance practices and the certification requirements. It emphasizes the importance of mapping data flows, ensuring staff competence and awareness, modifying processes, and conducting penetration tests to secure internet-facing technologies against external attacks.

20:04

🛠️ Tools and Strategies for GDPR Compliance

The paragraph introduces Cyber Comply as a tool to streamline GDPR compliance, offering modules for DPIAs, incident management, and mapping compliance to laws and regulations, integrated with an ISO 27001 management system. It discusses the need for automation in risk assessments and compliance documentation, as well as the importance of a robust platform for maintaining data consistency and security.

25:07

🤝 Support and Resources for Euro Privacy Certification

The final paragraph offers support and resources for organizations pursuing Euro privacy certification. It suggests consulting with experts for a gap analysis and implementation plan, mentions the availability of GDPR practitioner training, and highlights the in-house penetration testing team. The paragraph concludes with an invitation for further contact and assistance in achieving Euro privacy compliance.

30:08

📌 Q&A Session on Euro Privacy and GDPR Compliance

The Q&A segment addresses various questions about Euro privacy certification, including the difference between BCRs and certification, the possibility of self-certification, and the relationship between Euro privacy and other standards like ISO 27001 and ISO 27701. It also discusses the implications of using Gmail and AWS for data transfers and the application process for Euro privacy certification.

35:11

📚 Closing Remarks and Future Webinars

The closing paragraph thanks attendees for their participation and provides information about upcoming webinars that will delve deeper into specific aspects of Euro privacy compliance. It emphasizes the continued support available for those on their journey to certification and encourages the use of the provided services to ensure a safe, secure, and compliant business practice.

Mindmap

Keywords

💡GDPR Compliance

GDPR Compliance refers to the state of adhering to the regulations set forth by the General Data Protection Regulation, a legal framework that governs data protection and privacy in the European Union. In the video, GDPR compliance is the central theme, as the webinar discusses pathways to achieving and demonstrating this compliance, particularly through the Europe Privacy certification mechanism.

💡Alan Calder

Alan Calder is introduced as the host of the webinar and the founder of I.T. Governance, which is a company that plays a significant role in the field of cybersecurity and privacy. His mention in the script establishes his authority and expertise on the subject matter of GDPR and data privacy.

💡I.T. Governance

I.T. Governance is the main company within the ERC International Group and is highlighted as a global leader in GDPR and ISO 27001. The company's role is to provide services that help businesses achieve peace of mind regarding their information security and privacy, which is a key message in the context of GDPR compliance.

💡Europe Privacy

Europe Privacy is a certification mechanism recognized by the European Data Protection Board, designed to demonstrate compliance with GDPR. The script discusses its role, benefits, and the process for organizations to achieve this certification, which simplifies the demonstration of GDPR compliance to various stakeholders.

💡ISO 27001

ISO 27001 is an international standard that specifies the requirements for an information security management system. In the script, it is mentioned as a global standard that I.T. Governance helps businesses comply with, and it is also related to the Europe Privacy certification process, indicating a connection between information security and data privacy.

💡Data Protection Officer (DPO)

A Data Protection Officer is a role within an organization that is responsible for ensuring that the organization's data protection measures comply with GDPR. The script notes that Europe Privacy certification is currently available only to organizations required to appoint a DPO, emphasizing the importance of this role in data privacy compliance.

💡Data Flow Mapping

Data Flow Mapping is a process of documenting and visualizing the movement of data within an organization. In the context of the video, it is a requirement for Europe Privacy certification, helping organizations demonstrate awareness of where their data is processed and transferred, which is crucial for GDPR compliance.

💡Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment is a process of evaluating the risks of proposed processing operations to the rights and freedoms of individuals. The script mentions DPIAs as part of the Europe Privacy certification criteria, indicating the importance of proactively identifying and mitigating data protection risks.

💡Binding Corporate Rules (BCR)

Binding Corporate Rules are internal policies adhered to by a company and its subsidiaries for data protection and privacy. The script contrasts BCR with Europe Privacy certification, suggesting that while BCRs are internal, the certification provides an external validation of GDPR compliance.

💡Penetration Testing

Penetration Testing is the practice of simulating a cyber attack on a system to identify vulnerabilities. The script mentions penetration tests as a requirement for Europe Privacy certification, emphasizing the need for organizations to demonstrate robust security measures to protect against external attacks.

💡Cyber Comply

Cyber Comply is a tool mentioned in the script that helps automate various aspects of GDPR compliance, including DPIAs and incident management. It represents a technological solution to streamline and maintain GDPR compliance, which is a key aspect of the discussion on achieving Europe Privacy certification.

Highlights

Introduction to Europe's privacy certification as a gateway to certified GDPR compliance.

Alan Calder, founder of I.T. Governance, hosts the webinar with 25 years of experience in cybersecurity and privacy.

I.T. Governance's partnership with Euro privacy and their role in GDPR and ISO 27001 compliance.

The importance of demonstrating GDPR compliance to clients, especially for data processors.

Euro privacy as the first certification mechanism by the European Data Protection Board.

Benefits of Euro privacy certification, including legal compliance and improved trust with customers.

Core criteria of Euro privacy certification and its coverage of all GDPR areas.

Certification's validity for three years with surveillance visits and recertification process.

The significance of data flow mapping for GDPR compliance and breach management.

How Euro privacy certification simplifies the demonstration of GDPR compliance.

The role of ISO 27001 in preparing for Euro privacy certification.

Steps to achieve Euro privacy certification, starting with a gap analysis.

Importance of staff training and awareness in GDPR and Euro privacy compliance.

CyberComply tool's role in automating GDPR compliance for Euro privacy certification.

How Euro privacy certification provides a competitive advantage and risk reduction.

The webinar's Q&A session addressing questions on BCRs, self-certification, and the application process.

Final thoughts on the value of Euro privacy certification for GDPR compliance.

Transcripts

play00:00

the broadcast is now starting all

play00:02

attendees are in listen only mode

play00:22

ladies and gentlemen good afternoon and

play00:25

welcome to this webinar on Europe

play00:28

privacy introducing what could be your

play00:31

gateway to certified gdpr compliance

play00:36

my name is Alan Calder I'm your host

play00:39

for this afternoon I'm the founder of

play00:41

I.T governance which is the main company

play00:43

in the ERC International

play00:46

Group I've been involved in the cyber

play00:49

security and privacy world for some 25

play00:52

years I've written a number of books on

play00:54

gdpr on cyber security

play00:57

and of course it governance is a global

play01:02

leader in the world of gdpr and

play01:05

particularly through ISO 27001 we have

play01:10

pushing 200 people in the business we've

play01:13

been at it for about 20 years we've

play01:15

served some 12 000 clients across five

play01:17

continents and we recently became a an

play01:20

official partner of Euro privacy and you

play01:23

can read more about that on the Euro

play01:26

privacy website

play01:29

today's webinar really is going to be

play01:31

focusing on Europe privacy you'll notice

play01:34

that you are all on mute and that's

play01:37

designed to ensure that there's no

play01:38

background noise and so on but as I go

play01:40

through the webinar

play01:43

um I'm sure you'll find that there are

play01:45

questions you want to ask please do use

play01:46

the question function in your go to

play01:49

webinar control panel that's the chunk

play01:53

of functional text and icons that will

play01:57

be set on your screen there's a question

play02:00

line in there you can click on it you

play02:02

can type questions into that question

play02:04

box and when we come to the Q a section

play02:06

which will be about 40 or 45 minutes

play02:08

from now I will okay the questions I'll

play02:11

read out whatever questions there are

play02:13

and then assuming that I can I'll answer

play02:15

the question for everybody so everybody

play02:17

knows both the question and the answer

play02:20

so that's the format for today

play02:23

I.T governance as a business is a

play02:27

company who which is built around the

play02:29

logic that our expertise our expertise

play02:32

in information security

play02:34

in privacy and deployed in your business

play02:37

should give you peace of mind that

play02:40

enables you to focus on doing what you

play02:42

do best in serving your clients we've

play02:44

carried out more than 1300 organizations

play02:47

working with clients to deal with either

play02:49

twenty seven thousand one compliance

play02:52

1600 cyber security and privacy projects

play02:55

in one sort another more than seven

play02:57

thousand cyber essential certifications

play02:59

and we've helped uh some 1100 companies

play03:03

on their broader governance risk

play03:05

managements and compliance activity so

play03:08

we have a huge amount of experience that

play03:11

we can draw on to deliver services to

play03:15

our clients and that of course form part

play03:18

of the background and content of

play03:21

the webinar today

play03:24

so um what am I going to talk about and

play03:27

look first of all give an introduction

play03:28

to Euro privacy and what its role is in

play03:31

achieving gdpr compliance we look at the

play03:33

benefits and key principles of Europe

play03:35

privacy certification we'll have a brief

play03:38

look at how you can make gdpr compliance

play03:41

start your gdpr compliance journey and

play03:44

then some practical advice and solutions

play03:45

to uh to get you going so let's start

play03:49

with the origins of the Europe privacy

play03:51

certification as you all know gdpr ukg

play03:56

EU gdpr what's now known as EU gdpr has

play04:01

been around since May 2018 it's been in

play04:04

force effective since May 2018 but at

play04:07

first became a law in May 2016 so it was

play04:10

a two-year transition period and of

play04:12

course one of the big questions that

play04:14

existed right the way through the

play04:16

transition period and businesses how do

play04:18

we prove that we are gdpr compliant

play04:20

we've done everything we think we should

play04:22

do how do we prove that we're gen

play04:24

genuinely compliance and that is a an

play04:26

important question because you have

play04:29

clients asking you that that's relevant

play04:31

not only to just normal services that

play04:34

you provide but particularly if you are

play04:37

a data processor when of course the

play04:40

controller who's providing the data

play04:41

you're processing specifically needs to

play04:43

know whether or not your gdpr compliant

play04:45

it's also a useful aspect of dealing

play04:48

with breaches and so on a supervisor

play04:50

Authority will say and are you gdpr

play04:52

compliance of course the moment you're

play04:54

going to go say yes to the best of our

play04:56

ability or the best of our knowledge of

play04:58

the final Arbiter has typically been a

play05:01

judge and a case being brought you

play05:03

either win or lose Europe privacy

play05:06

changes that substantially so it's a

play05:08

significant step forward for all

play05:10

organizations it's the first

play05:12

certification mechanism

play05:15

just by the European data protection

play05:17

board as a European data protection seal

play05:20

article 42 of gdpr defined that seals

play05:26

certificates could come into existence

play05:29

that would demonstrate compliance with

play05:32

the edpr or with particular skills

play05:34

requirements the case may be and Europe

play05:37

obviously therefore as a certificate as

play05:39

a certification mechanism enables

play05:41

organizations to demonstrate their data

play05:43

processing activities comply with gdpr

play05:46

and by extension because

play05:49

extension is negotiated with

play05:53

other countries with other relevant

play05:55

National and international regulations

play05:56

so you just think about what does that

play05:59

shift mean if we can simply have a

play06:01

certificate that says we're compliant

play06:03

it's a huge simplification of a whole

play06:07

calendars that exist talking to

play06:10

clients talking to Regulators talking to

play06:13

stakeholders and partners

play06:15

your privacy was developed through the

play06:17

European research Horizon program in

play06:20

2020 co-funded by the European

play06:24

commissioner by Switzerland approved in

play06:27

October 2022 by the European data

play06:29

protection board and it's managed by the

play06:32

European Center for certification and

play06:33

privacy based in Luxembourg it's

play06:36

recognized in all 27 member states of

play06:39

the European Union it's a pan-eu

play06:42

certification and is applicable to both

play06:45

data controllers and data processes

play06:48

it's available only to organizations

play06:50

that are required to appoint a DPO so at

play06:54

this stage anyway one of the core

play06:57

requirements before you can get

play06:58

certified is are you required to have a

play07:00

data Protection Officer so

play07:03

uh so that's kind of relevant to

play07:04

everybody

play07:05

certification to be achieved

play07:07

organizations have to meet

play07:09

the core criteria the Euro privacy gdpr

play07:13

core criteria they cover various aspects

play07:16

of data processing and protection and

play07:18

allow organizations to assess Reliance

play07:20

compliance in respect of the lawfulness

play07:23

of your data processing how you deal

play07:26

with processing special data data

play07:28

subjects rights and your compliance with

play07:30

the requirements around

play07:32

measifying and protecting the rights of

play07:35

data subjects the response

play07:37

responsibilities of data controllers the

play07:40

responsibilities of data processors to

play07:43

data controllers the security of

play07:46

processing of data and how you deploy

play07:48

data protection by Design the management

play07:50

of data breaches deployments of dpias

play07:54

where they're acquired how your DPO

play07:56

operates and remembering dpas have to be

play07:59

in the UK and the EU Independence of the

play08:03

processing on which they comment and how

play08:06

data is transferred personal data is

play08:07

transferred to third countries or to

play08:10

International organizations all the core

play08:11

areas of gdpr are covered by Euro

play08:15

privacy certification and a certificate

play08:17

is valid for three years and the core

play08:22

criteria are complemented by contextual

play08:25

checks and controls around technology

play08:26

and domain specific obligations and of

play08:29

course Technical and organizational

play08:31

measures checking controls to ensure

play08:34

that they meet security requirements so

play08:36

it's a fundamental do you or do you not

play08:38

comply pdpr certification

play08:43

International trademark has registered

play08:45

obviously across the EU and a number of

play08:46

other jurisdictions its recognition

play08:49

extends Beyond EU borders means it's

play08:52

relevant for organizations in the US or

play08:55

the UK who are providing Services into

play08:57

the European Union that are required to

play08:59

have a DPO and the gdpr compliance if

play09:03

you can buy it to the whole of your

play09:05

operation certainly it can apply in the

play09:07

context of the personal data you're

play09:10

processing in scope for gdpr compliance

play09:12

and it demonstrates that the

play09:14

organization has a serious commitment to

play09:17

high data protection standards and

play09:19

compliance with gdpr on a global sale so

play09:22

you can think of it as an international

play09:23

trademark that generates gdpr compliance

play09:26

or you can look at it simply as how do

play09:28

we demonstrate to our EU customers that

play09:32

we are gdpr compliant

play09:35

you think about benefits obviously the

play09:39

first major benefit is demonstrating

play09:41

legal compliance and I can't I just

play09:43

can't stress enough how useful it is to

play09:46

be able to go no I don't have to uh

play09:49

write a letter I just simply give you my

play09:51

certificate number we are gdpr compliant

play09:54

we're also UK gdpr compliant because the

play09:58

extension negotiated with the UK we can

play10:00

demonstrate that we comply with UK gdpr

play10:02

which is currently only slightly

play10:04

reference to EU gdpr or pivoter in

play10:07

Canada as their case may be so it's a

play10:09

it's a solid demonstration of compliance

play10:13

with EU gdpr and a growing number of

play10:16

other National or jurisdictional data

play10:18

privacy regulations

play10:21

should enable you to demonstrate to

play10:24

customers that they can trust you so the

play10:25

improved trust uh the commitment that

play10:28

you're making it's data protection

play10:29

should really build trust with customers

play10:31

partners with regular authorities with

play10:33

stakeholders and should therefore give

play10:35

you a competitive Advantage we're still

play10:38

really at the early adopter very

play10:40

beginning of the early adopter stage in

play10:43

um

play10:45

curve for Europe privacy and so the

play10:48

first organizations will be able to say

play10:50

you know we are so far ahead of our

play10:52

competitors in terms of demonstrating

play10:54

our commitment to protecting personal

play10:56

data remembering the personal data

play10:57

protection has become a much much bigger

play10:59

issue for particularly consumers over

play11:02

the last five or seven years

play11:05

certification reduces the risk of

play11:07

non-compliance fines reduces the risk of

play11:11

legal issues related to the data

play11:13

protection because

play11:15

um you know that if you have a breach

play11:18

and you know remember you're going to

play11:19

have breaches whether you're

play11:21

EU privacy certified or not what the

play11:25

Civic enables to demonstrate and answer

play11:26

the question of were your gdpr compliant

play11:29

is yes we are we have external audits we

play11:32

have a certificate we were compliance so

play11:33

your risk of major exposure uh when you

play11:37

have to report a breach to a supervised

play11:39

Authority is by definition a

play11:41

significantly reduced simply because you

play11:43

can demonstrate beyond the doubt that

play11:45

you are gdpr compliant

play11:48

so the the if you like boiling that down

play11:51

to uh some of the key principles

play11:53

lawfulness of data processing

play11:56

demonstrating as part of your auditing

play11:58

the certification is carried out by an

play12:01

independent third-party certification

play12:02

orders so exactly the same logic as for

play12:05

ISO 27001

play12:07

um a certification body like BSI or dnv

play12:10

one of those who have become an

play12:12

accredited uh Euro privacy certification

play12:15

body or do an audit and certify your

play12:18

compliance with the standard a

play12:20

consultancy body a partner like I.T

play12:23

governance will provide services that

play12:25

help you become compliant but we won't

play12:27

do the certification audits so

play12:30

lawfulness of data processing uh it's a

play12:33

vehicle requirement so part of the

play12:35

process of preparing for Euro privacy

play12:38

certifications making sure that you're

play12:40

very clear about lawfulness and

play12:42

processing and that your processing is

play12:43

all being carried out in compliance with

play12:45

your legal obligations

play12:48

I'm respecting and upholding rights of

play12:50

individuals regarding personal data the

play12:53

eight rights of data subjects around for

play12:56

instance access rectification Erasure

play12:58

and so on demonstrating that those are

play13:01

all in place that you have mechanisms

play13:04

that enable people to exercise those

play13:07

rights to make it easy and

play13:08

straightforward for them to do so and

play13:10

that you're carrying out you can

play13:12

demonstrate that you are

play13:14

clearly delivering undefined data

play13:18

controller responsibilities you're

play13:20

managing personal data in line with the

play13:23

requirements of the standard and that

play13:26

will extend to areas in which you're a

play13:28

joint controller with an organization or

play13:31

there are two controllers processing

play13:33

data simultaneously but be really clear

play13:35

about the delineation of data controller

play13:37

responsibilities and applying them and

play13:39

being accountable for the the

play13:42

application of the six data protection

play13:44

principles

play13:47

processor making sure that your

play13:50

processing is in compliance to the gdpr

play13:52

and that means handling data

play13:54

specifically in compliance with the

play13:56

documented requirements of the data

play13:59

control level controllers for whom

play14:00

you're doing the processing so the first

play14:02

four major key principles of Europe

play14:06

privacy certification

play14:08

security of processing and data

play14:10

protection by Design and default equally

play14:13

important in gdpr is of course the

play14:16

general data protection regulations that

play14:18

is about protecting data and the

play14:21

breaches that you have to report are

play14:22

breaches because they compromise the

play14:25

confidentiality Integrity or

play14:27

availability of data in a way which

play14:29

poses a risk to the rights and freedoms

play14:31

of natural persons and so demonstrating

play14:34

the implemented robust security measures

play14:36

and data protection principles is

play14:38

another key element of your gdpr

play14:40

compliance we've for a long time said

play14:42

privacy and cyber security on different

play14:45

sides of the same coin and that's

play14:47

exactly what gdpr says and that's

play14:50

exactly what the European certification

play14:52

recognizes and goes beyond just simply

play14:54

saying you need to do data security it

play14:58

says if you want an ISO 71 72 if you

play15:00

have an ISO twenty seven thousand one

play15:03

certificate that will serve to

play15:04

demonstrate without you needing to do a

play15:06

whole bunch more in the certification

play15:08

orders that you have a compliance data

play15:12

protection regime so um there's a

play15:15

logical step from ISO 27001

play15:18

certification which in the scope you

play15:22

would logically include personal data

play15:24

and that would build into the next step

play15:27

of getting your overall processing

play15:30

personal data certified of your privacy

play15:33

certification as a 27 000 is a major

play15:35

building block um of that

play15:38

how you manage data breaches so instant

play15:40

response uh um and being able to track

play15:42

if gdpr requires you to track what you

play15:44

do with incident response so using an

play15:46

incident response tool that um Audits

play15:49

and keeps information around how you

play15:50

handle uh incident incidents is another

play15:53

key building block of

play15:56

um

play15:57

your privacy compliance data protection

play15:59

impact assessments remember doing a dpia

play16:01

isn't always necessary but identifying

play16:04

whether or not you needed one is always

play16:06

necessary when there is a significant

play16:09

change in the way in which you process

play16:11

data for the deployment of a significant

play16:14

new piece of personal data processing

play16:18

software so a dpia process that may or

play16:22

may not lead to carrying out a dpia

play16:24

appointments of a DPO where that is a

play16:27

where that is mandated and managing

play16:29

transfers of personal data in compliance

play16:31

with with Euro with gdpr and that

play16:35

particularly applies to third countries

play16:38

like the United States and for the EU

play16:41

all of the countries who are currently

play16:44

recognized as having adequate data

play16:46

protection regimes

play16:48

and of course what happens beyond that

play16:50

and the recent data transfer mechanism

play16:53

the theor of privacy that the EDP be

play16:56

assigned off on and the European Council

play16:58

has signed off on the labels transfer of

play17:00

data between the EU the UK Switzerland

play17:03

and the us legally is currently a key

play17:07

component of

play17:09

managing International transfer as a

play17:12

person like remember International

play17:13

transfers of personal data can include

play17:15

the transfer of information like cookies

play17:18

data assuming that you're still using

play17:20

cookies that can include the transfer of

play17:23

personal data because you're using a an

play17:27

email

play17:29

provider who is based in the United

play17:31

States so so all of those components

play17:34

have to be addressed so key building

play17:36

blocks of Europe privacy certification

play17:38

are things you should be doing anyway uh

play17:40

what Europe privacy as a standard does

play17:41

is encourage you to put all of those

play17:44

things together and make sure you're

play17:45

doing them consistently and consistently

play17:47

well and I'll come back to the logic of

play17:49

doing that on a platform which enables

play17:52

you to link the identification of risks

play17:55

to the protection of personal data

play17:58

through to how you manage data breaches

play18:01

to dpias to transfers of personal

play18:04

relation to be able to handle all of

play18:05

those in a platform environment which

play18:07

means that you've got consistency of

play18:09

data a consistency of data processing

play18:11

that a

play18:13

an external auditor can review and can

play18:15

see how robustly you handle is a key way

play18:18

to build a long-term Euro privacy

play18:21

certification remember it's a three-year

play18:22

certificate you have surveillance visits

play18:24

through the three-year period a

play18:26

recertification at the end of the

play18:28

three-year period and being able to

play18:30

demonstrate that you can do all of that

play18:32

is part of how you get certification so

play18:35

key building blocks of

play18:37

Euro privacy certification

play18:40

your privacy as a certificate should

play18:42

align absolutely with your current gdpr

play18:45

compliance activity that seems pretty

play18:47

logical to me Euro privacy is a

play18:50

structured approach to how you go about

play18:52

complying with gdpr so um you know while

play18:55

you might think of gdpower starting with

play18:57

article one and working all your way

play18:59

through to the bit just before it tells

play19:01

supervising authorities and the edpb how

play19:04

to behave that's what you've got to do

play19:06

but what your ability does is if you

play19:08

like gives you a really structured way

play19:10

to think about

play19:11

gdpr compliance what the building blocks

play19:14

are and how you go about doing that

play19:17

so it encourages of course it's a

play19:19

management system continuous Improvement

play19:22

certification carriages continuous

play19:24

Improvement in data protection practices

play19:26

and that's not just because gdpr

play19:28

regulations evolve but because the

play19:32

requirements of gdpr is that you deploy

play19:34

uh

play19:36

functionality or technology that is

play19:39

state of the art to manage risks to

play19:43

write some freedoms of data subjects and

play19:45

and that means you've got to continue

play19:46

evolving your management system you've

play19:48

got to continue learning from incidents

play19:51

you've got to continue deploying the

play19:52

learnings into making your processes

play19:54

work better so that you don't have a

play19:56

repeat what

play19:57

Regulators supervising authorities hate

play20:00

to see as the fact that you have this

play20:02

data breach and you have the same data

play20:03

breach and then you have the same data

play20:05

breach at time and time again you should

play20:06

be learning from them you know the the

play20:09

UK Ico just in the last four or five

play20:12

weeks observed that in the last five

play20:15

years the most commonly reported data

play20:17

breaches and this use of carbon copy in

play20:19

an email where a list of email addresses

play20:22

that should go into the BCC field in the

play20:25

email yet mistakenly

play20:27

plug it into the CC field which means

play20:30

that everybody else can see who got an

play20:31

email which could be a breach of gdpr

play20:35

because it might involve the email might

play20:38

include sensitive information for

play20:39

instance which will tell everybody else

play20:41

on the list that everybody else on the

play20:44

list is

play20:45

whatever it is has a particular illness

play20:47

so misuse of carbon copy is a common

play20:50

thing if it happens once you should be

play20:53

working out how to improve on the

play20:55

activity inside the organization so it

play20:57

doesn't happen again

play20:58

regularly compliance much simpler

play21:01

customer checks way simpler it's makes

play21:06

your life much easier from a global

play21:08

business point of view when you've got

play21:10

to fill in those increasingly long rfps

play21:16

are you gdpr complaint you should just

play21:18

be able to go here's my Euro privacy

play21:20

certificate yes we are gdpr compliant

play21:22

I'm not going to answer the questions

play21:24

because by definition we are compliant

play21:26

so it should be operationally as well as

play21:29

legally and practically a genuine

play21:33

Improvement and simplification of your

play21:35

working life

play21:38

how do you go about

play21:40

tackling your privacy how do you start

play21:43

the journey from your current state of

play21:46

gdpower compliance to Euro currency

play21:49

certification

play21:50

and it's logically a strategic approach

play21:53

you want to align what you currently do

play21:56

in terms of gdpr compliance with the

play21:59

requirements of the Euro privacy

play22:01

standards so

play22:03

um as I said Europe privacy provides a

play22:06

strategic approach so look the framework

play22:08

look at the blocks the building blocks

play22:10

and look at what you currently do in

play22:12

terms of gdpr to make sure that what you

play22:15

are doing meets the requirements of each

play22:17

of those blocks rather than trying to

play22:19

work your way through all of the Clauses

play22:21

one by one you can just simply go block

play22:23

by block how do we comply with what gdpr

play22:25

requires

play22:27

foreign

play22:30

principles where they are specific

play22:32

principles into your documentation into

play22:35

your existing data processing procedures

play22:37

so that you can demonstrate that your

play22:40

gdpr compliance is

play22:42

within the Euro privacy framework so

play22:45

these specific building blocks the

play22:46

principles all want to be clearly

play22:49

identified in the documentation in your

play22:51

staff awareness training and so on so

play22:52

that everybody understands that you're

play22:55

not just gdpr compliant you are you're a

play22:57

privacy compliant you have a Euro

play22:59

privacy compliance certificate

play23:01

and see the key steps that you take is

play23:04

number one is the gap analysis uh lo and

play23:07

behold virtually every regulatory or

play23:09

framework compliance project we'll start

play23:11

with a gap analysis because of course

play23:13

you're already doing a number of things

play23:14

that you should be doing and what you

play23:16

want to find out is the gap between what

play23:18

you are doing and what you should be

play23:19

doing and so a gap analysis either using

play23:23

a tool or with a an external consultant

play23:26

Society governance or somebody like that

play23:28

who knows their way around the standard

play23:29

will be able to look at what you

play23:31

currently do look at the requirements of

play23:33

the standard and tell you what the Gap

play23:34

is between

play23:36

as is and to be and give you a map

play23:39

towards cheating that so that's the uh

play23:42

the starting point it enables you then

play23:44

to put together a a plan that outlines

play23:48

the steps the resources the timelines

play23:49

required to integrate the Euro privacy

play23:52

principles

play23:53

some of your gdpr compliance activity it

play23:56

might have fallen off over the course

play23:58

the last four or five years because you

play24:00

know life

play24:01

um and and that

play24:03

means you can identify the extent to

play24:06

which you're ready to meet the core

play24:07

criteria and be assessed for compliance

play24:12

one of the key elements of uh Europe

play24:15

privacy and this is it's in the standard

play24:18

is that you are able to demonstrate that

play24:21

you've mapped data flows and mapping

play24:22

data flows is a requirement because it's

play24:24

how you can demonstrate that uh you know

play24:28

where your data is going when you have a

play24:30

data breach you need to be able to

play24:32

identify what steps you need to take to

play24:34

deal with the data breach you need to be

play24:36

clear about where data is Flowing beyond

play24:39

the European Union or Beyond a country

play24:41

which hasn't recognized as adequate data

play24:44

protection regime because you need to

play24:45

have in place additional protections to

play24:49

ensure the lawfulness of that processing

play24:52

there's also an article 30 requirement

play24:54

that your data flow mapping is clear

play24:57

about what data you are processing and

play25:00

and so

play25:01

and many organizations don't actually do

play25:03

this very well so gdpr compliance looks

play25:06

for you to do that it could be a major

play25:08

area that you've got to focus on early

play25:09

on and your data flows may have changed

play25:12

since you became vdpr compliant and so

play25:15

using typically a data flow mapping tool

play25:18

uh is a way that you can not only map

play25:20

what you're currently doing but creates

play25:22

a robust basis for maintaining and

play25:25

updating that as time goes on because

play25:27

you know you change flows as

play25:30

as life happens you find better ways to

play25:32

do things so you need to be able to

play25:33

update data flow in a robust environment

play25:37

so Gap analysis A compliance or an

play25:41

implementation plan which would start

play25:43

probably with data flow mapping or

play25:45

updating your data flow mapping how

play25:47

ready are you for a gdpr Euro privacy

play25:51

compliance assessment

play25:55

competence and staff awareness both

play25:57

critical areas you need to have people

play25:59

who are managing gdpr who are competent

play26:01

to do that so A gdpr practitioner

play26:04

certification

play26:05

a Euro privacy awareness and making sure

play26:09

that your staff training and awareness

play26:10

includes gdpr and any of the specific

play26:13

Euro privacy principles so you need to

play26:16

build that out make sure that you can

play26:18

demonstrate that your staff or aware

play26:21

because you know simple things like

play26:24

um uh data subjects access requests

play26:28

could be passed as you know to any

play26:30

member of staff so training staff to

play26:32

recognize their obligations uh to know

play26:34

how to deal with data protection uh

play26:37

requirements as a key part of gdpr

play26:39

compliance and therefore of Europe

play26:40

privacy uh certification

play26:43

so you modify your processes you might

play26:46

not need to do anything dramatic it

play26:48

might just be minor changes in in

play26:50

documentation or in activity to make

play26:51

sure the key principles particularly

play26:54

around data security measures if you

play26:56

don't have ISO 27001 implementing either

play27:00

implementing ISO 27001 as part of your

play27:02

Euro privacy strategy or working on how

play27:05

you're going to demonstrate that you

play27:07

have in place data protection by Design

play27:08

and by default

play27:11

I have clarity about how you've run

play27:13

about compliance make sure that in your

play27:16

Incident Management for instance you've

play27:17

got a process in place not simply to

play27:19

manage incidents but to track how you do

play27:21

manage the incident because you're going

play27:23

to have to report on that to uh to a

play27:26

supervising Authority if you have an

play27:27

incident how you've gone about it how

play27:29

you've met the requirements for

play27:30

determining whether it's a serious

play27:33

breach or not that you've done what you

play27:35

need to do in the time scales uh

play27:37

delivered and finally you need to carry

play27:40

out penetration testing so it's

play27:44

the pro state-of-the-art mechanisms to

play27:46

protect data is in gdpr Euro privacy is

play27:48

explicit you need to penetration tests

play27:51

you need to do penetration tests on your

play27:53

internet facing

play27:55

um

play27:58

Technologies and infrastructure to make

play28:00

sure that they are secure against

play28:02

external attack and penetration so

play28:06

all of those steps carry them out

play28:09

Europe privacy certification is likely

play28:11

unless you're already well prepared to

play28:13

be something which takes a number of

play28:15

months to get to the benefits are

play28:17

worthwhile because of you know we said

play28:19

them all at the beginning because of

play28:20

being able to demonstrate compliance

play28:21

because of being compliant because of

play28:24

what it helps you win in the way of

play28:25

competitive advantage and dispel in the

play28:28

way of risk exposure and cost but it's a

play28:31

series of blocks steps that you need to

play28:33

take

play28:35

I mentioned cyber comply it's a tool

play28:38

which is from from our point of view

play28:41

almost essential to build gdpr

play28:44

compliance it combines a gdpr set of

play28:48

modules that do dpias that um uh

play28:52

can can handle Incident Management that

play28:55

enable you to map compliance to laws and

play28:58

regulations with an ISO 27001 management

play29:01

system which can deal with information

play29:03

security so it's an integrated set of

play29:06

services there's a huge roadmap of

play29:09

development going on with cyber comply

play29:11

that will bring a whole series of

play29:13

documentation automation around

play29:15

documents into the system but it's

play29:19

gives you a seamless automation for gdpr

play29:22

compliance which is really going to be

play29:26

we think increasingly basic to making

play29:29

your privacy certification really work

play29:31

you want to be able to automate risk

play29:33

assessments you want to be able to

play29:34

automate the reviews and updates of risk

play29:36

assessments and ISO compliance

play29:38

documentation your typical compliance

play29:40

team one or two people having to manage

play29:42

gdpr cyber security compliance with more

play29:45

and more certifications and regulations

play29:47

coming along it just gets to be

play29:49

impossible to do on aspensary

play29:51

spreadsheets are simply not robust and

play29:53

they're very dependent on the individual

play29:55

so as long as the individual never

play29:56

leaves or Goes Sick

play29:58

um it probably might be okay you need a

play30:00

platform that never goes on leave or is

play30:02

sick you need cost effects of

play30:05

Maintenance you need complete

play30:07

integration needs updates for gdpr

play30:10

regulations being fed through and you

play30:12

need to be able to navigate the

play30:14

complexities of gdpr compliance with

play30:17

some kind of ease

play30:20

uh you need a dashboard that tells you

play30:23

what's going on all of those things you

play30:25

can get with cyber comply so do go and

play30:28

have a look at Cyber comply you can link

play30:30

through you can arrange to be given a

play30:34

demonstration of the platform

play30:35

um it's obviously a something you can

play30:37

you can access and use on ongoing basis

play30:40

but do have a look at Cyber compliant

play30:42

we'll make uh Euro privacy and gdpr

play30:44

certification massively simpler and more

play30:47

robust

play30:50

apart from cyber comply there are a

play30:52

number of obvious ways that you can

play30:54

address getting up to scratch for Euro

play30:57

privacy apart from a gap analysis just

play31:00

talk to us email us following this

play31:03

webinar we can arrange to talk to you

play31:05

about a consultant who can come and do a

play31:08

gap analysis for you and put together an

play31:10

implementation plan but more

play31:12

particularly implementational

play31:13

consultancy but how do we do it what do

play31:16

you need to do we're not in the our

play31:17

Europe currency partner but we have a

play31:19

number of our Sultans who have been

play31:21

signed off by

play31:23

the Europe privacy team as competent to

play31:26

deliver Euro privacy compliance we can

play31:30

do penetration tests we've got in-house

play31:31

penetration testing team that can

play31:33

deliver a Euro privacy related

play31:35

penetration test to meet their standards

play31:38

we of course can do

play31:41

um

play31:43

what ifs we can do gdpr practitioner

play31:45

training the whole panoply of everything

play31:48

that you need to get yourself gdpr and

play31:50

Europe privacy compliance we can help so

play31:53

do either when you get the slides after

play31:56

the webinar and and we will be circling

play31:58

the slides to everybody within a day or

play32:00

so you can click through or do simply

play32:02

just

play32:04

email us afterwards or call us

play32:06

afterwards and say you'd like to speak

play32:07

to somebody about how you can be helped

play32:10

at tackle your approaching be the first

play32:12

in your sectoral region to become Euro

play32:15

privacy compliant

play32:17

that brings me to the end of what I had

play32:20

planned to cover in this really meant to

play32:23

be an introductory session on Euro

play32:25

privacy we have a number of other

play32:27

webinars planned to go into more detail

play32:30

about particular aspects of Europe

play32:32

privacy compliance so that we can help

play32:34

those organizations who are addressing

play32:36

it on their own

play32:37

do that uh

play32:40

um just simply to keep you clear about

play32:41

how things are moving ahead you can

play32:43

obviously find out more about your

play32:46

privacy gdpr compliance or anything else

play32:48

by going on to one of our websites UK EU

play32:51

or United States lots of ways you can

play32:54

contact us and that brings us through to

play32:58

Q and A so

play33:01

um let me just turn to that if you do

play33:03

have questions just repeating what I

play33:05

said earlier in your go-to webinar

play33:08

um

play33:10

in your case we have in our dashboard

play33:11

there is a q a uh function and you can

play33:15

simply go into that you can type into it

play33:17

any questions which you have what I will

play33:20

do is I

play33:22

go through the questions I will answer

play33:23

them uh I'll read the question out I'll

play33:26

answer the question and and hopefully

play33:28

that will give you the answer that

play33:30

you're looking for

play33:32

so

play33:33

um

play33:35

what's the difference between BCR and

play33:38

certification if a company has BCR is

play33:42

certification recommended as well well

play33:45

um if you have binding corporate rules

play33:48

bcrs binding corporate rules those are

play33:51

recognized by the uh super supervisor

play33:55

Authority you've designed them

play33:56

specifically to meet the requirements of

play33:58

your own organization and they

play34:02

demonstrate to the supervising Authority

play34:04

that you have a mechanism for managing

play34:06

uh your gdpr compliance but binding

play34:10

corporate rules is not necessarily the

play34:11

same as being able to demonstrate to uh

play34:15

uh stakeholders customers that your gdpr

play34:19

compliance uh Euro privacy certificate

play34:22

should be on the basis of having VCRs in

play34:25

place assuming your bcrs are

play34:26

comprehensive

play34:28

um should be relatively easy to get but

play34:30

you're a privacy certification in our

play34:32

view anyway uh gives you a big step

play34:35

forward because it is an external

play34:37

validation an external demonstration by

play34:40

a third-party certification body that

play34:42

your gdpr compliant that your binding

play34:45

corporate rules are gdpr compliant that

play34:47

you've done everything required it's a

play34:50

stakeholder customer demonstration so

play34:52

while you've always got to validate it

play34:54

for yourself that would be our view of P

play34:58

Euro privacy compliance I would build it

play35:01

on the top of binding corporate rules

play35:03

if adpr is not required for company can

play35:05

the company perform a self-certification

play35:07

that demonstrates compliance well um

play35:10

there's nothing ever stopping an

play35:12

organization doing a self-certification

play35:13

but here at previously at the moment

play35:15

doesn't provide a framework by which

play35:17

your self-certification can be

play35:19

recognized we we hope that that will

play35:22

happen fairly quickly

play35:24

that there are a number of organizations

play35:26

who require DPO and their data

play35:29

processing obligations are likely

play35:31

therefore to be more significant than

play35:34

organizations that don't require a DPO

play35:36

which is for us logically why

play35:39

the initial stages anyway the

play35:41

certification focus on DPO um yes you

play35:43

know as with ISO 27001 you can say that

play35:47

you are compliant with Euro privacy it's

play35:48

worthwhile doing there are benefits at

play35:51

the point when hopefully the Euro

play35:53

privacy Mark gets extended to all other

play35:56

organizations it'd be very easy then for

play35:58

you to make the step on from where you

play36:00

are to formal certification

play36:04

what's the difference between BCR and

play36:05

certification of the company I think

play36:07

I've just answered that

play36:09

uh just answer that yes we'll just

play36:11

replace the need for a company to put in

play36:13

place sccs and bcrs well not necessarily

play36:17

because international data transfers is

play36:20

one of the areas that Europe privacy

play36:23

certification looks at so

play36:25

um if you think about

play36:27

the issue of sccs or bcrs from the point

play36:30

of view of a third party say a data

play36:34

subject looking at your organization

play36:36

not clear whether you process data where

play36:39

you process data you are supposed to be

play36:41

clear that data is processed outside

play36:45

the European Union or the UK as the case

play36:48

may be and the basis on which that's

play36:49

lawful and if it's being processed in a

play36:53

country that for which there is not an

play36:55

adequacy finding there has to be in

play36:57

place either for an international

play36:59

organization BCR or binding corporate

play37:01

rules or standard contract clause and

play37:04

standard contract Clauses are exactly

play37:06

that they come from the edpv or

play37:10

the supervisor Authority and their

play37:12

standard causes that you have to adopt

play37:14

and comply with

play37:16

data subject doesn't know whether you've

play37:18

got theirs or not it's not a badge you

play37:19

can put on your website or on your

play37:21

letterhead saying you know we have

play37:22

standard contract Clauses doesn't mean

play37:24

very much to a

play37:27

to a data subject or to a key customer

play37:30

of yours a European certificate does in

play37:33

exactly the same way as an ISO 27001

play37:35

certificate is something you can put on

play37:37

your website you can put on your

play37:39

letterhead you can put on your business

play37:40

cards it's a an externally third-party

play37:43

validated

play37:45

um certificate of compliance covering a

play37:48

broad range of issues that Simply Having

play37:49

secs done so um secs and or BCR was not

play37:54

and or secs or BCR those are if they're

play37:58

legally industry they're legally

play37:59

necessary you're a privacy certification

play38:01

is something which sits on top of that

play38:03

and tells the outside world that you've

play38:05

done those things absolutely correctly

play38:09

um

play38:10

does it governance cover training

play38:12

implemental auditor for the

play38:14

certification at the moment we cover uh

play38:17

training for gdpr practitioner and for

play38:20

uh um for lead audits we are trying to

play38:23

arrange to become a recognized trainer

play38:25

for practitioner for implementer and

play38:28

auditor for Euro privacy because it's a

play38:31

logical extension to the range of areas

play38:34

that we already offer training in and we

play38:36

hope to have good news on that front

play38:37

relatively

play38:38

Sue

play38:40

thanks for the session how important

play38:43

would you say it is for an organizations

play38:45

Right iso 27 30 27 000 certified Square

play38:48

for Europe privacy certification as well

play38:52

um and that depends on how important

play38:54

personal data processing is to your

play38:56

organization I would hope that in Euros

play38:59

27001 certification you've already got

play39:02

personal data in the scope for the

play39:04

standard and you've therefore already

play39:05

got gdpr recognized as being under

play39:08

Clause 4.1

play39:10

um the when which you go about

play39:12

recognizing the requirements of

play39:14

interested parties around

play39:17

security of data processing if you've

play39:20

already done that if personal data

play39:21

processing is already in there well

play39:23

um Euro privacy is a Step Beyond

play39:26

ISO twenty seven thousand ISO 27001

play39:28

focuses primarily on the security of the

play39:30

processing your privacy says okay you're

play39:33

doing that are you also doing it

play39:35

lawfully are you also doing the

play39:37

processing completely in line with the

play39:39

requirements of

play39:41

um of gdpr so if you've got ISO 27001

play39:45

and you want to convince customers

play39:46

either corporate or directly corporate

play39:50

and indirectly individuals or directly

play39:53

personal data subjects then Europe

play39:55

privacy is the step one Beyond it if you

play39:58

think of iso 27 701 which is a personal

play40:02

information management

play40:03

be part of the scope of your 27001

play40:06

certification if you've got 27 701 in

play40:09

your um ISO 27 000 but I almost

play40:12

certainly say new pins I do Euro privacy

play40:15

because it should be a cinch it should

play40:17

be very easy to get to but Euro privacy

play40:19

benefits Focus uh Beyond ISO 27001 on

play40:24

telling data subjects that you are

play40:26

processing data both securely and

play40:28

lawfully you pay the necessary and

play40:31

required attention to the rights of data

play40:35

subjects

play40:38

is this something to look at if our

play40:40

organization is purely UK based

play40:42

um so so the answer is that your privacy

play40:46

already has secured a extension to cover

play40:50

UK gdpr

play40:52

um if you want to be able to demonstrate

play40:55

that your UK gdpr compliant Euro privacy

play40:57

is a certification that enables you to

play40:59

do that it's the same set of

play41:00

requirements UK gdpr at the moment is

play41:03

not fundamentally different from EU gdpr

play41:06

the differences are in scope of data

play41:08

processing in definition of

play41:10

international borders and so on but

play41:11

otherwise it's essentially the same law

play41:13

so

play41:14

here at privacy because it has an

play41:16

extension to cover the UK is a very

play41:19

sensible thing for UK organizations to

play41:21

do that wants to be able to demonstrate

play41:23

to its customers that it's gdpr

play41:26

compliant

play41:30

um

play41:34

would using Gmail and AWS constitute

play41:37

data transfer if no data is accessed in

play41:39

the USA you have mentioned using emails

play41:41

earlier we treat data flowing via US

play41:43

servers you can't treat data flowing via

play41:46

US servers as datron Transit I'm afraid

play41:48

because the gdpr specifically says that

play41:53

data that is processed outside of the EU

play41:57

can only be done so lawfully if it's

play42:00

being processed in the country for which

play42:01

there is a

play42:03

um is he finding from the European

play42:05

commission or for which there is for

play42:09

which you have standard contract Clauses

play42:10

in place or which if you're an

play42:12

international organization you have

play42:13

binding corporate rules in place all of

play42:16

those having done a risk assessment to

play42:19

ensure that the processing of data in

play42:22

the third country is going to be done at

play42:26

a level of security similar to what you

play42:28

get in the European Union and up until

play42:30

very recently with the failure of the EU

play42:33

U.S pregnancy Shield that did not

play42:36

include the US and processing data with

play42:38

AWS or female with with any processor

play42:42

that is processing data in the US

play42:46

there's no such thing as in transit in

play42:48

transit is processing it falls with the

play42:50

definition of processing would have been

play42:53

illegal

play42:54

recently agreed data protection

play42:58

framework between the EU and the U.S

play43:02

legal it's worth doing it's worth

play43:05

getting on top of as quickly as you can

play43:06

the edpb is recognized that the European

play43:09

commission has recognized it

play43:12

noib and Max schrems has promised to

play43:16

tackle its European court of justice on

play43:19

account of uh the the U.S store

play43:24

enables the state to access personal

play43:27

data in a way that isn't allowed in the

play43:29

European Union but for the time being

play43:30

it's legal it might be legal for several

play43:32

years so

play43:33

um you can do it but you need to be very

play43:35

clear that that's legal based on which

play43:37

you're processing data in the US I hope

play43:38

that's

play43:39

not too worrying answer for you at the

play43:43

moment

play43:44

how does this fit with ISO 27701

play43:48

um I I already answered that but I'll

play43:50

just cover it again ISO 27 701 is a ISO

play43:54

standard for a personal information

play43:56

management system you can be certified

play43:58

against it only if it is within the

play44:01

scope of your existing ISO 27001

play44:05

certificate so you'll get a 27001

play44:07

compliance figure that includes the

play44:10

statement that you have um ISO 27 701 in

play44:13

place you've been audited for compliance

play44:15

with that standard

play44:17

um it's a personal information

play44:18

management system it will cover pretty

play44:21

much everything that your privacy covers

play44:24

it's designed to be a generic personal

play44:26

information management system but again

play44:28

if you're thinking about how do I

play44:31

convince stakeholders how do I convince

play44:35

um customers particularly personal uh

play44:38

personal

play44:39

individuals that I'm dealing with that

play44:42

we are

play44:43

pdpr compliance your privacy is a Step

play44:46

Beyond that should be very easy for you

play44:47

to get a Euro privacy certificate on the

play44:49

basis of a 27 0001 27 701 combined

play44:54

certificate because you shouldn't be if

play44:55

anything pretty well there

play44:58

um there might need to be a little bit

play44:59

more very specific work done around

play45:01

making sure that your lawfulness and

play45:03

data processing that the way in which

play45:05

you meet the requirements around human

play45:07

rights the way in which we deal with

play45:09

data processes or very specifically gdpr

play45:12

compliance but you should be pretty well

play45:13

there

play45:19

is do keep the questions coming

play45:23

um

play45:24

is this something uh indeed eating how

play45:28

does this fit with isotrades and so when

play45:29

I want to dealt with is the

play45:31

certification only for gdpr for

play45:33

international organizations in respect

play45:35

several data

play45:36

um laws how will it help when having to

play45:40

justify compliance with other laws so

play45:42

the answer is you need to find

play45:44

the certification is your privacy

play45:47

certification the Euro privacy body

play45:51

recognizes that organizations

play45:53

increasingly have to comply with more

play45:55

than one set of regulations so they are

play45:57

negotiating with other countries for

play46:00

recognition uh certificates so that the

play46:03

European certificate can be extended to

play46:05

cover compliance with those countries

play46:07

and that includes right now for instance

play46:10

the UK I believe it includes Canada's

play46:12

pivoter um so you just want to check

play46:14

with us or with Bureau privacy team

play46:17

they're able to tell you which other

play46:19

countries are currently covered by the

play46:22

Europe privacy certificate but the

play46:23

single European certificate as long as

play46:26

you're clear about what you want to have

play46:27

in scope you should be able to extend to

play46:30

cover a growing number of countries so

play46:32

it should become over time the single

play46:34

most straightforward way of

play46:36

demonstrating compliance with all of the

play46:39

things with which you have to comply and

play46:41

even if Europe privacy doesn't today

play46:42

meet demonstrate in able to demonstrate

play46:45

compliance and everything you have to do

play46:47

I would still do it if you have to have

play46:49

say EU gdpr compliance because it gives

play46:52

you the framework that you can then

play46:54

simply continue extending from a

play46:56

certification point of view as other

play46:58

countries come within the Ambit of the

play47:01

EP certificate

play47:04

finally

play47:07

does how does ISO 27000 2022 change

play47:11

comparing to ISO 27001

play47:15

2013. and the good news for you in

play47:18

answer that question is that we've done

play47:20

a whole series of webinars on exactly

play47:22

that on the differences between ISO

play47:24

twenty seven thousand one 2013 and ISO

play47:26

27001 2022 on how to go about making the

play47:30

transition you can access all of those

play47:33

they are on our website if you can't

play47:36

easily swap them please do email us and

play47:39

we'll send you a link directly that

play47:41

enables you to go and have a look at

play47:42

those those webinars on on the

play47:46

transition

play47:47

and ladies and gentlemen that kind of

play47:49

looks as though we're getting to the end

play47:50

of uh questions on uh this

play47:57

what is the application process and how

play47:59

is costing assessed a good a good

play48:02

question the there are two steps one is

play48:05

you need to make sure that you're ready

play48:06

for certification so uh you do that by

play48:09

talking to us you email us we'll talk to

play48:12

you we'll we'll give you a scope we'll

play48:14

work out what it is you need to do we'll

play48:15

give you a price for certification you

play48:17

go to a

play48:19

you're a privacy accredited

play48:21

certification body uh you've gone to

play48:23

Euro privacy website uh and you'll be

play48:26

able to see which certification bodies

play48:27

are accredited to do certifications and

play48:30

the process of getting a price of doing

play48:32

that is exactly the same as getting a

play48:34

price for an iso twenty seven thousand

play48:36

one certification uh you you team you

play48:39

talk about scope you get a price you get

play48:42

a competing price but that's it's

play48:44

exactly as you get an ISO 27 109001

play48:47

certificate

play48:51

um is the scheme accredited if the

play48:53

website says it's aligned then it's

play48:55

aligned it's not accredited I think is

play48:57

is the answer to that question

play49:00

and ladies and gentlemen I think my

play49:03

voice is going to pack up on us so I

play49:06

would like to thank you all for having

play49:08

been on this webinar uh today if it's

play49:12

been useful

play49:14

data as I said we'll be sending the

play49:16

information out to everybody

play49:20

um uh so you'll be able to access it

play49:21

separately

play49:23

um but there will be another series of

play49:25

webinars as I said please do come on

play49:27

enjoy those find them useful and if we

play49:29

can help you on your Euro privacy

play49:31

Journey uh please take full advantage of

play49:34

our services in the EU the UK and the us

play49:38

to help you do that thank you all I hope

play49:40

you have a safe secure and compliant

play49:43

rest of September bye

Rate This

5.0 / 5 (0 votes)

Related Tags
GDPR CompliancePrivacy WebinarAlan CalderData ProtectionISO 27001Cyber SecurityEurope PrivacyCertification GuideLegal ComplianceData GovernanceWebinar Q&A