SlideShare a Scribd company logo
25.05.2018
EU GENERAL DATA
PROTECTION REGULATION
HTTPS://WWW.IITR.DE/EN/EUDATAP/
25.05.2018
ePRIVACY REGULATIONHTTPS://WWW.IITR.HTTPS://WWW.IITR.DE/EN/EUDATAP/DE/EN/EUDATAP/
HTTPS://WWW.IITR.HTTPS://WWW.IITR.DE/EN/EUDATAP/DE/EN/EUDATAP/
DATA PROTECTION
IS ABOUT
ONLINE AND
OFFLINE
DATA PROTECTION
IS ABOUT
PROCESSES
DATA PROTECTION
IS A
MANAGEMENT TASK
These are the ‘‘8 Commandments“
Physical access control —> key lock / transponder
Admission control —> password
Data access control —> access management
Entry control —> logfiling
Transfer control —> process control
Order control —> vendor control
Availability control —> avoid to lose controll
Separation rule —> data use only for committed needs
Technical and Organisational Measures (T
DATA PROTECTION
IS BETWEEN
negligent and
grossly negligent
E-PRIVACY
IS ABOUT
COOKIESAND REQUIRES AN
OPT-IN OPTION
E-PRIVACY
IS ABOUT
PASSWORDSMIN:8 DIGITS, CAPITALS, SYMBOLOLS, NUMBERS
E-PRIVACY
IS ABOUT
IMPRINT
NAME, LEGAL-INFO,
CONTACTDETAILS., REG NUMBERS,
VAT NO.
ONE CLICK TO GET THERE FROM
EACH PAGE…
E-PRIVACY
IS ABOUT
APPLICATIONS
DON´T REQUEST FOR CVS BY EMAIL - JUST
BY CONTACT FORM
EU GENERAL
DATA
PROTECTION
REGULATION
IS ABOUT
MONEY
up to 4% of the
world wide
turnover
Penalty:
Management has to make
sure that all options to avoid
data breaches have been
implemented.
State of the technical standard and reasonable
commissioned
data
processing
CDP ARE NEEDED IF YOU HAVE
CONTRACTORS YOU GRANT
ACCCESS TO PERSONALDATA
OF YOUR CLIENTS/
CUSTOMERS TO INSURE THEIR
PROCESSES OF
DATAHANDLING (ACCESS
DATA TO SERVER OR ONLINE
APPLICATIONS WITH
CUSTOMER DATA) ARE
MATCHING THE
REQUIREMENTS AS WELL.
Everything is not allowed…
The data protection law
shows the exceptions!
THANK YOU
DANKE
GRACIAS
AGRAIR

More Related Content

Data protection policies cristian arndt