GDPR IMPLEMENTATION SISCON 2018 CONFERENCE 13/09/2018

Similar documents
GDPR Awareness. Kevin Styles. Certified Information Privacy Professional - Europe Member of International Association of Privacy professionals

First Components Ltd, Savigny Oddie Ltd, & Datum Engineering Ltd. is pleased to provide the following

EXIN Privacy and Data Protection Foundation. Preparation Guide. Edition

This policy sets out how Legacy Foresight and its Associates will seek to ensure compliance with the legislation.

IAB Europe Guidance THE DEFINITION OF PERSONAL DATA. IAB Europe GDPR Implementation Working Group WHITE PAPER

Personal Research Data. 25 Sept 2018 Solveig Fossum-Raunehaug (Research Support Office)

Ethics and technology

Ocean Energy Europe Privacy Policy

The General Data Protection Regulation and use of health data: challenges for pharmaceutical regulation

Privacy Policy SOP-031

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Privacy framework

Towards Code of Conduct on Processing of Personal Data for Purposes of Scientific Research in the Area of Health

Data Protection and Ethics in Healthcare

CCTV Policy. Policy reviewed by Academy Transformation Trust on June This policy links to: T:Drive. Safeguarding Policy Data Protection Policy

General Questionnaire

RESEARCH PAPER. GDPR is a state of mind, not just a technology solution. June Sponsored by

The GDPR and Upcoming mhealth Code of Conduct. Dr Etain Quigley Postdoctoral Research Fellow (ARCH, UCD)

IET Guidelines for Volunteers: Data Protection

Biometric Data, Deidentification. E. Kindt Cost1206 Training school 2017

This Privacy Policy describes the types of personal information SF Express Co., Ltd. and

Interest Balancing Test Assessment on the processing of the copies of data subjects driving licences for the MOL Limo service

Building DIGITAL TRUST People s Plan for Digital: A discussion paper

CCTV Policy. Policy reviewed by Academy Transformation Trust on June This policy links to: Safeguarding Policy Data Protection Policy

2018 / Photography & Video Bell Lane Primary School & Children s Centre

Communication and dissemination strategy

12 April Fifth World Congress for Freedom of Scientific research. Speech by. Giovanni Buttarelli

The new GDPR legislative changes & solutions for online marketing

Wireless Sensor Networks and Privacy

Standards and privacy engineering ISO, OASIS, PRIPARE and Other Important Developments

Pan-Canadian Trust Framework Overview

Rules for Game Digital All Cash

Ethics Review Data Sharing Bridging Legal Environments

Application pack Level 3 Certificate in Housing Practice blended learning open access

Principles and Rules for Processing Personal Data

ASSEMBLY - 35TH SESSION

Human Rights in the era of Information and Communication Technology

Privacy and the EU GDPR US and UK Privacy Professionals

ISSUANCE AND CIVIL REGISTRATION

Photography and Videos at School Policy

New Age Vital Statistics Services: What They Do and Don t Do

LAB3-R04 A Hard Privacy Impact Assessment. Post conference summary

HBM4EU project. Information, Invitation and Informed Consent Lisbeth E. Knudsen, Berit A. Faber. Information and recruitment of participants

EU-GDPR The General Data Protection Regulation

Why AI Goes Wrong And How To Avoid It Brandon Purcell

Rules for Game The Christmas Cracker

Swedish Proposal for Research Data Act

GDPR Implications for ediscovery from a legal and technical point of view

Technology transactions and outsourcing deals: a practitioner s perspective. Michel Jaccard

Secure identity and electronic signatures essential for digital trust

Computer Ethics. Dr. Aiman El-Maleh. King Fahd University of Petroleum & Minerals Computer Engineering Department COE 390 Seminar Term 062

SEFI Keynote Talk. André Rogaczewski, CEO/ Partner Netcompany. Page 1

What Do Librarians Want? How Google Has Changed Traditional Expectations

Privacy Management in Smart Cities

AU PAIR REGISTRATION FORM

Privacy engineering, privacy by design, and privacy governance

IoT in Health and Social Care

Lecture 7 Ethics, Privacy, and Politics in the Age of Data

The Information Commissioner s response to the Draft AI Ethics Guidelines of the High-Level Expert Group on Artificial Intelligence

System Audit Checklist

CIPO Update. Johanne Bélisle. Commissioner of Patents, Registrar of Trade-marks and Chief Executive Officer

Pokémon Bank. Getting Started. Introduction. Passes. Using Pokémon Bank

Integrating Fundamental Values into Information Flows in Sustainability Decision-Making

Xena Exchange Users Agreement

The Alan Turing Institute, British Library, 96 Euston Rd, London, NW1 2DB, United Kingdom; 3

Implementation of Directive 2010/63/EU: - the animal welfare perspective

Our position. ICDPPC declaration on ethics and data protection in artificial intelligence

ITAC RESPONSE: Modernizing Consent and Privacy in PIPEDA

2

2018/2019 HCT Transition Period OFFICIAL COMPETITION RULES

Interaction btw. the GDPR and Clinical Trials Regulation

Artificial Intelligence, Business, and the Law

Violent Intent Modeling System

SPONSORSHIP AND DONATION ACCEPTANCE POLICY

HL7 Standards and Components to Support Implementation of the European General Data Protection Regulation (GDPR)

YOUNG PERSONS PRIVACY NOTICE

Workshop on Legal and Policy Frameworks for Geospatial Information Management

Realising the FNH-RI: Roadmap. Karin Zimmermann (Wageningen Economic Research [WUR], NL)

Business Perspectives on Smart Cities Sensors, Big Data Lasse Berntzen

Privacy Procedure SOP-031. Version: 04.01

CENSUS DATA COLLECTION IN MALTA

Robert Bond Partner, Commercial/IP/IT

GUITAR PRO SOFTWARE END-USER LICENSE AGREEMENT (EULA)

EU businesses go digital: Opportunities, outcomes and uptake

Justice Select Committee: Inquiry on EU Data Protection Framework Proposals

Comparison ibeacon VS Smart Antenna

SWEDEN. Statement. H.E. Ambassador Mikaela Kumlin Granit. International Atomic Energy Agency. General Conference. 62 nd session.

Whatever Happened to the. Fair Information Practices?

PRIVACY ANALYTICS WHITE PAPER

The EU's new data protection regime Key implications for marketers and adtech service providers Nick Johnson and Stephen Groom 11 February 2016

GAMING POLICY FRAMEWORK

DaPIS: an Ontology-based Data Protection Icon Set


Undergraduate Resource Series

You should see the following screen when you first login to Student E-Service

Dr Jon Kirkpatrick Head of Connected Cities

2 3, MAY 2018 ANKARA, TURKEY

Analysis of Privacy and Data Protection Laws and Directives Around the World

Big Data and Personal Data Protection Challenges and Opportunities

A Pattern Catalog for GDPR Compliant Data Protection

Submission to the Governance and Administration Committee on the Births, Deaths, Marriages, and Relationships Bill

Transcription:

GDPR IMPLEMENTATION SISCON 208 CONFERENCE 3/09/208

FOUNDED IN 999 AND TODAY ~70 CONSULTANTS AND ~600 INTERVIEWERS SISCON CONFERENCE 208 2

WE CONDUCT FULL SERVICE MARKET RESEARCH YET SPECIALIZED ANALYZE INFORMATION SURVEY Business Units Public & Politics Aviation MARKET RESEARCH Transportation Commercial TREND EVALUATION STATISTICS SISCON CONFERENCE 208 3

90% OF WHAT WE DO INVOLVES PERSONAL DATA MOST EVEN SENSITIVE ID-number Name E-mail address Sexual conviction Date of birth Gender Race Credit card number Health information Photos Genetic information Address Interests Employee ID Phone number Personality test License number Religion! Access control Personal performance Political preference Severe social problems Family information System logs Login name/ initials Passport no. Position GPS information IP-address Size shoes and clothes Union memberships Electronic trails Travel information Biometric information Criminal record Video observations MACaddress SISCON CONFERENCE 208 4

WE WERE LATE AND NEEDED SPEED AND PRAGMATIC SOLUTIONS!! SISCON CONFERENCE 208 5

Probability GDPR COMPLIANCE WAS A SIGNIFICANT CHALLENGE FOR EPINION Risk matrix Main risks Mitigation Almost certain (5) 3 Almost certain/moderate: Delay, i.e. implementation after 25 th of May-8 Implementation of initiatives have been prioritized according to criticality e.g. VN tasks and SharePoint before 25 th of May-8 Likely (4) 2 Almost certain/moderate: Deep understanding across all employees difficult e.g. many locations and high in/out rate 2 New educational programme will incorporate training in GPDR and WOWs and signing of privacy and security policies Moderate (3) 3 Almost certain/moderate: Historical personal data overlooked, i.e.. not deleted or anonymized 3 Continuous and frequent communication of why we need to do this together with the possible upside = more control/less risk Unlikely (2) 4 Likely/severe: Breach towards respondent or client any of the 6 EU citizen rights 4 Admit (if we have a weak case), apologize and compensate if needed. Enforce a earnings loop across the whole of Epinion Remote () 5 Likely/minor: Stickiness towards old ways of working and cultural resistance 5 Keeping GDPR compliance high on the agenda going forward. Develop on-going internal audit checks and process updates Minimal () Minor (2) Moderate (3) Major (4) Severe (5) 6 Moderate/moderate: File and database server migration to MS Azure troublesome (time, loss of data, downtime etc.) 6 Migrate one-by-one and PS IT to be in DK for 4 weeks to assist the migration. Always ensure a back-up until new up and running. Impact Note: The numbers in the squares indicate the amount of risks with the given impact/probability score. 7 Moderate/minor: Missed sales opportunities due to internal resources being occupied with GDPR implementation 7 The new Operations Director will take the internal DPO role and be the overall accountable for GDPR => resources released SISCON CONFERENCE 208 6

VIETNAM IS A NON-SECURE COUNTRY, I.E. TASK TRANSFER TO DK Tasks which are to be transferred from VN to DK/NO before 25th of May-8: Norge Danmark Vietnam. Sample withdrawal 2. Phone number enrichment 3. Interview status 4. Sample processing 5. Sample uploading 6. E-mail invitation 7. Sample data maintenance 8. Uni-Login tool 9. Interview status 7 large projects which are to be transferred from VN to DK/NO before 25th of May-8:. AKU 2. RVU 3. TU 4. Ørsted 5. Dementia 6. SUF 7. Boligsiden SISCON CONFERENCE 208 7

OVERALL, WE IDENTIFIED 7 TO DOS TO ENSURE GPDR COMPLIANCE 2 Clean-up of historical data across all servers, applications, personal hardware etc. Having the contractual agreements in place working with clients a must have 7 3 Obtaining consent from data subjects e.g. web, focus groups, newsletters, invitations etc. 4 Strict and standard procedures when requests from data subjects 5 Transition of tasks from Professional Services to DK/NO as VN classified as non-secure country Market us as a trustworthy player taking privacy (very) seriously 6 Implement new ways to store, access and share data SISCON CONFERENCE 208 8

OUR CAR ANALOGY TO CREATE COMMON UNDERSTANDING AND BACKING Would you agree it is good manners to... Ask if you may borrow it 6 Be careful nothing unwanted happens while you borrow it (speeding tickets, damages etc.) State what purpose you need to borrow it for 2 7 If an accident does happen, while you borrow it, tell the owner as quickly as possible Say how long you need to borrow it 3 8 Correct any mistakes while in your possession (e.g. pay parking or speeding tickets) Deliver it back on time 4 9 Return it at once if the owner wants it back Not use it for other purposes than you have stated 5 0 Not keep a copy of the key just in case you want to use it again? Now replace the words borrow with treat and it with personal data then you have an overview of many of the principles for treating personal data in the GDPR. All of a sudden, it is a lot less complicated, right? SISCON CONFERENCE 208 9

THE COST OF GDPR HAS BEEN SIGNIFICANT AND SALES HAVE SUFFERED GDPR/cost Sales/budget SISCON CONFERENCE 208 0

WE MARKET OURSELVES AS A GDPR PARAGON BECAUSE WE ARE Epinion Privacy Policy Since analyzing data is our core business, we handle loads of data every day. These data take various forms: Market data, brand data, institutional data - and obviously also personal data such as e-mails, phone numbers, political beliefs, travel experiences and sociodemographics. Being one of the leading companies within market research and analysis - and being privileged with more than 0 years of experience with handling of personal data - we know the importance of privacy and trust and not least we apply the highest market standards. When you trust us with your personal data, it is our responsibility and privilege to earn that trust and safeguard your data in all possible ways. This means that we: Only use data for the specific purpose we obtain it for Always ask up-front for your consent to use the relevant data Never transfer data to 3rd parties without your explicit consent (or if we are legally bound to do so) Make sure to restrict access to data within the data processing period Anonymize data as soon as possible Delete data when it is no longer needed Have all necessary means of IT-security in place to protect our systems SISCON CONFERENCE 208

COMPLIANCE IS NOW OUR CORE FOCUS USING CONTROL MANAGER COMPLIANCE RULES POLICIES REGULATIONS LAW STANDARDS REQUIREMENTS TRANSPARENCY SISCON CONFERENCE 208 2

EPINION AARHUS EPINION COPENHAGEN EPINION HAMBURG EPINION LONDON HACK KAMPMANNS PLADS -3 8000 AARHUS C DENMARK T: +45 87 30 95 00 E: AARHUS@EPINIONGLOBAL.COM RYESGADE 3F 2200 COPENHAGEN N DENMARK T: +45 87 30 95 00 E: COPENHAGEN@EPINIONGLOBAL.COM ERICUSSPITZE 4 20457 HAMBURG GERMANY T: +43 (0)699 38046 E: HAMBURG@EPINIONGLOBAL.COM D ALBIAC HOUSE (ROOM 05-07) CROMER ROAD, HEATHROW CENTRAL AREA HOUNSLOW, TW6 SD T: +44 (0) 7970 020793 E: LONDON@EPINIONGLOBAL.COM THANK YOU! EPINION SAIGON TH FL, DINH LE BUILDING, DINH LE, DIST. 4, HCMC VIETNAM T: +84 8 38 26 89 89 E: HCMC@EPINIONGLOBAL.COM EPINION SINGAPORE 60 PAYA LEBAR ROAD #08-43 PAYA LEBAR SQUARE SINGAPORE E: CONTACT@EPINIONGLOBAL.COM EPINION STAVANGER EPINION VIENNA EPINION MALMÖ EPINION OSLO KLUBBGATEN 4 4006 STAVANGER NORWAY T: +47 90 7 8 99 E: STAVANGER@EPINIONGLOBAL.COM HAINBURGERSTRASSE 20/7 030 VIENNA AUSTRIA T: +43 (0)699 38046 E: VIENNA@EPINIONGLOBAL.COM ADELGATAN 5 222 MALMÖ SWEDEN E: CONTACT@EPINIONGLOBAL.COM BISKOP GUNNERUS GATE 2 055 OSLO NORWAY T: +47 97 73 50 E: OSLO@EPINIONGLOBAL.COM WWW.EPINIONGLOBAL.COM