EU General Data Protection Regulation (GDPR): An Implementation and Compliance Guide
- 3h 14m
- IT Governance Privacy Team
- IT Governance
- 2016
The EU General Data Protection Regulation (GDPR) will supersede the 1995 EU Data Protection Directive (DPD) and all EU member states' national laws based on it - including the UK Data Protection Act 1998 - in May 2018.
All organizations - wherever they are in the world - that process the personally identifiable information (PII) of EU residents must comply with the Regulation. Failure to do so could cost them up to 20 million, or 4% of annual global turnover in fines.
US organizations that process EU residents' PII can comply with the GDPR via the EU-US Privacy Shield, which replaced the EU-US Safe Harbor framework in 2016. The Privacy Shield is based on the DPD, and will likely be updated once the GDPR is applied in May 2018.
This book provides a detailed commentary on the GDPR, explains the changes you need to make to your data protection and information security regimes, and tells you exactly what you need to do to avoid severe financial penalties.
Product overview
EU GDPR - An Implementation and Compliance Guide is a clear and comprehensive guide to this new data protection law, explaining the Regulation, and setting out the obligations of data processors and controllers in terms you can understand. Topics covered include:
The role of the data protection officer (DPO) - including whether you need one and what they should do.
- Risk management and data protection impact assessments (DPIAs), including how, when and why to conduct a DPIA.
- Data subjects' rights, including consent and the withdrawal of consent; subject access requests and how to handle them; and data controllers' and processors' obligations.
- International data transfers to "third countries" - including guidance on adequacy decisions and appropriate safeguards; the EU-US Privacy Shield; international organizations; limited transfers; and Cloud providers.
- How to adjust your data protection processes to transition to GDPR compliance, and the best way of demonstrating that compliance.
- A full index of the Regulation to help you find the recitals and articles relevant to your organization.
The GDPR will have a significant impact on organizations' data protection regimes around the world. EU GDPR - An Implementation and Compliance Manual shows you exactly what you need to do to comply with the new law.
In this Book
-
Introduction
-
Privacy Compliance Frameworks
-
Role of the Data Protection Officer
-
Common Data Security Failures
-
Six Privacy Principles
-
Requirements for Data Protection Impact Assessments
-
Risk Management and DPIAs
-
Data Mapping
-
Conducting DPIAs
-
Data Subjects' Rights
-
Consent
-
Subject Access Requests
-
Controllers and Processors
-
Managing Personal Data Internationally
-
Incident Response Management and Reporting
-
GDPR Enforcement
-
Transitioning and Demonstrating Compliance
-
ITG Resources