2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

12
Data Protection Regulation Albin Zuccato Head of Information Security

Transcript of 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Page 1: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Data Protection Regulation

Albin ZuccatoHead of Information Security

Page 2: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Sentor in brief

Businessidea"Protectcompanies

informa0onassetsby

offeringqualifiedITsecurity

services"

Thecompany•  Foundedin1998

•  Selffinancedandvendorindependent

•  Excellentclientandstaffreten?on

•  Widerangeofclientsinvarioussectors

•  Securitycer?fica?ons

•  45+employees

Page 3: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Data Protec/on– is there a business case?

•  AssetProtec?on•  Personaldataisanimportantintangibleasset

•  Businessenabler/preventer•  Privacymaylooseyoumoney

•  Privacymaykillyourproduct

•  …privacymayaKractcustomers

DirectDamage•  Customerloss•  Datacorrup?onorloss•  Restora?ondamage

Recoverycost•  Inves?ga?oncost•  Systemcorrec?oncost

Legaldamage•  Courtcost•  Fines&Penal?es•  Liability

Reputa?ondamage•  Brandvalue•  Marke?ngcost•  Lossofcustomer/business

Page 4: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Timeline •  CommissionpreparedadraSin2012•  Parliamentvotesforgeneralprinciplesoftheregula?on,12.03.2014

•  Councilreachesagreementongeneralapproach,15.6.2015

•  TrialogebetweenEUCommission,EuropeanParliamentandCouncilstarted,24.06.2015

•  Trialogepartneragreedonroadmaptofinalizelealtextduring2015(inconjuc?onwithdataprotec?ondirec?veforlawenforcement),09.10.2015

•  Decisioncanbeinspring2016

4

Page 5: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Safe Harbor invalid

•  EuropeanCourtofJus?cedeclaredSafeHarborinvalid

• Writeacontract(dataprocessingagreement)•  Verifyiftherearegroundfortransfer•  Performanceofcontract•  Importantpublicinterest•  Vitalinterestofthedatasubject

•  Getthedatasubjecttogiveexplicteconsent

Page 6: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

The upcoming EU data protec/on regula/on

•  Lawfulnessofprocessing•  Personaldatalistwithprocessingpurpose

•  Datasubjectrights•  Mechanismstoretrieve,provide,correct,beforgoKenandforwardpersonalinforma?on

•  Electronicmeanstocommunicatewithdatasubjects

6

Page 7: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Security

•  Dataprotec?onbydesign•  CommissionandParliamentperceivepseudonymiza?onasasuitabletechnology

•  PrivacyRiskAnalysis•  Internalcontrolandauditproceduresforpersonaldataprocessing•  Documenta?oninfrastructure•  Enhanceincidentmanagementforprivacybreachrepor?ng

Page 8: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

8

•  Applicability•  IntheEUandinterna?onallyforEUci?zens

•  FreeServicesareincluded•  Amountofdatasubjects(500)andnotcompanysize

•  Interna?onaliza?onaspects•  Placewheredecisionsaremadecountsforinterna?onalorganiza?on

•  Transfertothirdcountrywillbebasedonthecountrieslegisla?on(safe,neutral,unsafe)

Applicability

Page 9: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Fines, liability and supervision

•  Datasubjecthasarightforcompensa?onfordamagesuffered

•  Es?matessayupto200000SEKperperson

•  Penal?esaccordingtocriminallawmaybedecided

•  Fines•  Warningmechanismwillavailibale•  Finesarecurrentlyasubjectfordiscussion(seenextslide)

•  Supervisionauthori?eshavetoworkinconcert(i.e.decisionsarebindingforall,leadauthorityforcrosscountry…)

Page 10: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Some ques/ons we get

10

Parliamentwantstosee100Mio€or5%

(CommissionandCouncil)Globalannual

turnover

Absencemechanismforrequest,chargeafee

0,5%(or250k€)

informa?onobliga?on,documenta?onorco-controller

1%(or500k€)

mostotheroffences2%

(or1000k€

Page 11: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

•  Thelawwillbedecidedin2016andenterintoforce2017

•  Dataprotec?onwillbecomeanissuefortheboard

•  Thereissomeworktodotobecomecompliant

Conclusion

Page 12: 2015 Albin Zuccato - Sentors frukostseminarium om dataskydd

Ques/ons