13
General Data Protection Regulation (GDPR) Project Kick-Off

General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

  • Upload
    others

  • View
    10

  • Download
    0

Embed Size (px)

Citation preview

Page 1: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

GeneralDataProtectionRegulation(GDPR)

ProjectKick-Off

Page 2: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

Agenda

•  Welcome

•  WhatisGDPR

•  Planofaction

•  Yourrole

•  NextSteps

Page 3: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

TheGDPRTeam-DataProtectionOfficer/ComplianceWhitneyGlenz-HumanResourcesRadhikaAyyar-InternationalProgramsEvieMyers-InformationTechnologyJimFritz-InformationSecurityHenryRose&DavidMaxwell

-ChiefInformationOfficerMidhatAsghar-EnrollmentServicesMichelleHill-Procurement&DisbursementMarieJohnson-AlumniRelationsEdieCharlot-Marketing&CommunicationsMauricePerkins

Page 4: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

IntroductiontoGDPR

Page 5: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

GDPRBasics•  GDPRsaysthatifyoucollectpersonaldataorbehaviorinformationfrom

someoneINanEUcountry,youaresubjecttotherequirementsoftheGDPR.

•  First,thelawonlyappliesifthedatasubjectsareINtheEUwhenthedataiscollected.ForEUcitizensoutsidetheEUwhenthedataiscollected,theGDPRwouldNOTapply.

•  GDPRwillregulatedatacontrollersandprocessorsbothintheEUandoutsideoftheEU.

•  GeneralDataProtectionRegulationisalegallyenforceableEUregulationpassedtoreplacetheDataProtectionDirective.

•  GDPRenforcementwillbeginMay25,2018.

Page 6: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

GDPR–10Tips

Page 7: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

ElementsoftheGDPR

•  DataflowsfromtheEUmustbeunderstoodandmapped

•  Datamustbelawfullyprocessed

•  Expandeddutiesforcontrollersandprocessors

•  Expandedrightsfordatasubjects

Page 8: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

ExamplesofActivitiesThatCouldBeSubjectToGDPR

•  ResearchinvolvingpersonslivingintheEU–  DatacollectedbyPVAMUresearchers

directly–  DatacollectedbyentitieslocatedintheEU

thentransferred/soldtoPVAMUresearchers

•  ProcessingofdatabyPVAMUforcontrollersorprocessorslocatedintheEU

•  PVAMUappsmarketedtopersonslivingintheEU

•  Internetbrowsingdata/cookiesofpersonslivingintheEU

•  PVAMUadmissionsdataregardingpersonslivingintheEU

•  DataofpersonslivingintheEUcollectedduringtherecruitmentofPVAMUstaff

•  DataofPVAMUprofessorsteachingabroad

•  DataofPVAMUstudents(studyingabroad)

•  DataofpersonslivingintheEUcollectedduringPVAMUfundraisingefforts

•  PVAMUPhonerecords•  PVAMUMedicalrecords•  Metadata&logs

–  Mailheaders,dooraccesslogs,libraryrecords

Page 9: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

PVAMUGDPRProject:Goal&ApproachGoal:PVAMUwillreviewGDPRrequirements,anddeveloparisk-basedcompliancestrategyandcorrespondingcomplianceprogram.Approach:•  People:engagetherightstakeholders,documentGDPRroles&

responsibilities•  Policy:provideprivacystatementsandsupportingtemplates&

documentation•  Process:assessandaddressprocessesinsupportofcompliance•  Technology:identifypossibletechnicalsolutionsenabling

compliance

Page 10: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

YourRole•  WorkingGroupParticipation

–  Activelyparticipateinall-stakeholdermeetingsandcontributetotheprogressoftheproject

–  ProvideinputtothedesignofongoingGDPRprogram–  Serveasaon-goingGDPRliaisonforyourpartoftheorganization

•  Process&documentdevelopmentandreview

–  IdentifydataflowspotentiallyregulatedbyGDPR–  ActivelyparticipateinworkingsessionstodocumentandanalyzeprocessesinyourorganizationthatmaybeimpactedbyGDPR

–  Utilizeandtakeownershipofon-goingprocessesanddocumentationdevelopedbytheproject(dataflowtemplate,etc.)

Page 11: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

TheGDPRTeam-DataProtectionOfficer/ComplianceWhitneyGlenz-HumanResourcesRadhikaAyyar-InternationalProgramsEvieMyers-InformationTechnologyJimFritz-InformationSecurityHenryRose

-InformationSecurityDavidMaxwell-ChiefInformationOfficerMidhatAsghar-RegistrarMichelleHill-TravelOfficeMarieJohnson

Page 12: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

•  UpdatePoliciesandProcedurestoreflectconsentandGDPRNoticeofRights

•  Provideupdatedpoliciesandprocedurestothecampuscommunity

•  DeveloplistofSummerTraveltoEUforFaculty/StaffandStudents

•  ScheduleGDPRProjectMeetingforLateSummer

•  DevelopwebsiteforGDPRatPVAMU

NextSteps

Page 13: General Data Protection Regulation (GDPR) Project Kick-Off · 2019-12-18 · (GDPR) Project Kick-Off Agenda • Welcome • What is GDPR • Plan of action ... progress of the project

OpenDiscussion