Showing posts sorted by relevance for query gdpr. Sort by date Show all posts
Showing posts sorted by relevance for query gdpr. Sort by date Show all posts

15 February 2018

A white paper by Microsoft on GDPR


On May 25, 2018, a European privacy law is due to take effect that sets a new global bar for privacy rights, security, and compliance.

The General Data Protection Regulation, or GDPR, is fundamentally about protecting and enabling the privacy rights of individuals. The GDPR establishes strict global privacy requirements governing how you manage and protect personal data while respecting individual choice—no matter where data is sent, processed, or stored.

Microsoft and our customers are now on a journey to achieve the privacy goals of the GDPR. At Microsoft, we believe privacy is a fundamental right, and we believe that the GDPR is an important step forward for clarifying and enabling individual privacy rights. But we also recognize that the GDPR will require significant changes by organizations all over the world.

We have outlined our commitment to the GDPR and how we are supporting our customers within the “Get GDPR compliant with the Microsoft Cloud” blog post by our Chief Privacy Officer Brendon Lynch and the “Earning your trust with contractual commitments to the General Data Protection Regulation” blog post by Rich Sauer, Microsoft Corporate Vice President & Deputy General Counsel.

Although your journey to GDPR may seem challenging, we are here to help you. For specific information about the GDPR, our commitments, and beginning your journey, please visit the GDPR section of the Microsoft Trust Center.

Get your copy of the White Paper here: www.microsoft.com

05 February 2018

11 things you must do now for GDPR compliance


On 25th May 2018, today’s Data Protection Act (DPA) will be replaced with the new General Data Protection Regulation (GDPR). This checklist highlights the 11 most important steps you can take now to make sure your data and processes remain compliant. 

According to the Information Commissioner’s Office (ICO), if you’re already DPA compliant, then most of your approach to compliance will remain valid come May 2018. However, there are some differences in GDPR, which means you’ll have to do certain things for the first time and some other things differently. Before we get into the specifics, here’s an overview of the GDPR and what it means for businesses and individuals. 

What is GDPR?
The point of the GDPR is to provide clarity and consistency for the protection of personal data. It imposes new rules on organisations that offer goods and services to people in the European Union (EU), or that collect and analyse data tied to EU residents, no matter where they’re located. The GDPR establishes: 

Enhanced personal privacy rights
Increased duty for protecting data
Mandatory breach reporting
Significant penalties for non-compliance

Read the full article here: www.clouddirect.net

14 May 2018

GDPR compliance deadline is approaching: 10 things to do right away


The European Union General Data Protection Regulation (GDPR) becomes fully enforceable on May 25, 2018. According to recent surveys, 60% of companies polled are going to miss the deadline; it's a sobering number considering how severe the fines and penalties could be for companies found to be noncompliant in the aftermath of a security breach. The reality is many businesses still do not understand what compliance with the GDPR really means.

With perhaps a few exceptions, every business that collects personal data from customers, clients, and vendors is going to experience a security breach where that data is exposed, comprised, and/or stolen. This inevitable fact is just one of the costs of doing business in an interconnected world. The GDPR does not, and cannot, expect businesses to patch unknown security vulnerabilities or avoid security incidents altogether. However, the GDPR does require businesses to make every effort to mitigate the damage security breaches have on people, particularly EU citizens.

To that end, it is vital that all enterprises take measured and documented steps to close security vulnerabilities, prevent security breaches, and mitigate the risks when prevention fails. The mere fact that an enterprise made a substantial and documented effort in this regard could be enough to establish GDPR compliance and avoid substantial fines and penalties after a security breach.

Here are 10 specific things your enterprise can and should do in preparation by the GDPR compliance deadline of May 25, 2018. (Note: The items on the list are not presented in any specific order—all of them are important and progress for each should be well-documented.)


06 April 2018

The top 5 things you should know about GDPR


The European Union's General Data Protection Regulation (GDPR) goes into effect May 25, 2018. Companies have been preparing for it for awhile but if you're still in the dark, it's not too late to get up to speed.

Here are five things to know about the EU's GDPR:

1. It's about data privacy. The GDPR attempts to give EU citizens more control over what data companies collect, store, and use.

2. It probably applies to your business. GDPR applies to every citizen of the EU and any business entity that transacts with them. Sell a t-shirt to a Frenchman? You need to deal with the GDPR.

3. It's pretty much any kind of data. Anything related to a person that can be used directly, or indirectly, to identify them is now regulated.

4. You have to get explicit permission to process personal data and your request must be in clear language. You can't use long legal documents or hide things in a privacy policy. And it has to be as easy to withdraw consent as it was to give it.

5. Penalties are big. If an enterprise violates the practices of the GDPR, it can be fined up to 4% of the company's global turnover or 20 million Euros, whichever is greater.


28 November 2017

6 misconceptions about GDPR - helpful advice from Cisco


Cisco has been helping thousands of businesses with their GDPR preparation, which means they’ve been asked pretty much every question there is to be asked on the topic. They have kindly summarised the most common questions that get asked, and have provided some practical answers for anyone who is currently on the path to GDPR compliance.

1) I only have to worry about GDPR if I get breached, right?

2) Where does GDPR give me the list of security things that I need to do?

3) What products do I buy to be GDPR compliant?

4) It is a European thing, so Brexit gets us out of it, surely?

5) Tell me about those fines again?

6) Didn’t the EU already have laws on this front? Surely I’m compliant already?


05 January 2023

Facebook's parent: Meta - gets over $400 million in GDPR fines

As of Wednesday 4th Jan, Meta has once again been hit with a major GDPR violation, earning itself more than $400 million in fines for its latest data privacy misstep. The EU’s Ireland-based Data Protection Commission levied two sets of fines after ruling that EU-based users have been illegally forced to accept personalized, targeted ads from both Facebook and Instagram.

This GDPR ruling is one of the most severe since GDPR was first instituted in 2018, but it’s certainly not Meta’s first expensive run-in with the regulation. In this report, we’ll share what we know about Meta’s latest violation, and we’ll dive a little deeper into Meta’s troubled past with GDPR.

www.techrepublic.com


17 November 2017

Most UK small businesses in the dark over GDPR


There is still much work to be done before UK SMEs are fully prepared for the EU’s General Data Protection Regulation (GDPR).

With the GDPR compliance deadline just over six months away, the UK’s small business community remains unsure about a number of related issues.

Small to medium enterprises (SMEs) are struggling to come to grips with what “personal data” really means, their customers’ new and extended rights, and whether the permissions they currently have to contact customers will meet the requirements of GDPR.


26 May 2018

GDPR - who says you can't have fun while tied up in red tape? ;0)


What did Blackbeard use to safely and securely enlist his crew?
GDP-Arrrrrrrr.

===

Do you know a specialist on GDPR?
Yes.
Can you give me his e-mail address?
No.

===

Knock knock
Who’s there?
GDPR
GDPR who?
I can’t tell you as you don’t have consent to process my data.

===

He's making a list
He's checking it twice
He's gonna find out who's naughty or nice
Santa Claus is in contravention of article 4 of the General Data Protection Regulation (EU) 2016/679

===

That's enough fun for now - back to the

23 May 2018

GDPR goes live on the 25th May! Wise words from Sage accounts...


GDPR data protection principles: Under the General Data Protection Regulation (GDPR), you need to make sure you have policies and procedures in place to cover the data protection principles. You can find more detail about this from the ICO website, but to help you, Sage has put together some of the key points.

Like you weren't already aware(!), but just to remind you that GDPR goes live on 25th May 2018!


12 March 2018

What is GDPR & how do I know if I’m affected?


This May will see a change in the rules governing management the personal data of EU citizens. Is your business ready for the changes to the way employee data is handled?

The General Data Protection Regulation (GDPR) is an EU regulation that will come into force on 25 May 2018. It centres around personal data protection for EU citizens, and aims to unify data privacy laws across Europe.

Many businesses and organisations that hold data will be affected. Non-compliance with GDPR can mean significant fines for those in breach, so for those that have not already done so, it is time to start preparing.

How do I know if I’m affected? According to EUGDPR.org, the new regulation “applies to organisations located within the EU but it will also apply to organisations located outside of the EU if they offer goods or services to, or monitor the behaviour of, EU data subjects”.

Any companies which process and hold personal data of EU subjects, no matter where the business is based, fall under the remit of GDPR. So yes, you are most likely affected.


22 May 2018

GDPR webcast: safeguarding individual privacy rights with the Microsoft Cloud


Join several Microsoft executives including, Brad Smith, President and Chief Legal Officer, for our May 25th webcast, Safeguarding individual privacy rights with the Microsoft Cloud, where they will be reinforcing our support for privacy and showcasing how the Microsoft Cloud can help accelerate GDPR compliance. In this webcast, we will highlight:

Show how you can use GDPR fundamentals to assess and manage your compliance risk.

Discuss how you can help protect your customers' data with built-in, intelligent security capabilities.

Cover how you can meet your own compliance obligations by streamlining your processes.


01 June 2018

Clear a path to cloud compliance - discover GDPR-compliant cloud services


Can your cloud provider cover off 80% of the controls you need to be GDPR compliant + help you with the final 20%? This one can. Watch this Microsoft Webinar talking through how compliance manager can support compliance.

The sheer amount of regulation, how fast it changes, and the need to show you comply with it are all challenges for companies. It's complex and time-consuming. And the picture only gets more complicated when it comes to cloud services: you need to work out how you will share the responsibility for protecting data with your cloud provider.

It's a job in itself. But it often falls to an individual to fit it in to their already busy schedule.

With Microsoft cloud, you get a platform you can trust. And support to configure and – just as importantly – prove compliance. With a lot of the heavy lifting taken care of, you can check progress and plan your path to compliance.

In this webinar, we give you clear ways to:
• Cut the level of human involvement in getting compliant.
• See how you're complying, regulation by regulation.
• Streamline the steps to compliance.
• Get audit-ready reports.

Watch the webinar now to discover smarter ways to comply.


04 May 2018

Office365 Webinar: Develop automatic data retention policies #GDPR


Organisations have more data than ever before. But unless they take the right approach, they can end up keeping everything. And that means it's hard to find what you need, or know if sensitive data is under threat, or compromised.

Microsoft Office 365 advanced data governance automates data retention by using intelligence. So you can meet the demands of the GDPR, keep information in case of emergency, find data rapidly – and still only retain what you need to.

In this webinar, you'll learn how you can:
Label sensitive information.
Make sure data goes through a review before being discarded.
Create and action policies.
Automate policies so they're applied across all relevant content.
Watch the webinar now to discover better data governance.

Register for this Microsoft Webinar to see how Microsoft Office 365 can help you to develop automatic data retention policies.


20 February 2020

GDPR: have you received a letter from the Information Commissioner’s Office (ICO) regarding the need for registration?


Have you received a letter received from the Information Commissioner’s Office (ICO) regarding the need for registration? These letters concern the need for small businesses to register with the ICO, in order to demonstrate to their clients that they take their data protection obligations seriously.

Now, these are not SPAM! Apart from some businesses which may be exempt, it is important that every business that processes information pays a fee to the ICO, otherwise, they may be fined under the Data Protection (Charges and Information) regulations 2018 Act. And these fines can be as large as £4,000!

The fee for a small business is usually only £40-£60 per annum. But all small businesses should refer to the ICO website to check their eligibility and pay if required.

Under the Data Protection (Charges and Information) Regulations 2018, individuals and organisations that process personal data need to pay a data protection fee to the Information Commissioners Office (ICO), unless they are exempt. Click here for the registration self-assessment test to see if you have to register / need to pay a fee.


20 April 2018

Need to carry sensitive data with you SECURELY?


Kingston Technology DataTraveler Vault Privacy USB 3.0 Hardware Encrypted Drive - Data Security to Safeguard Your Sensitive Business Information

Kingston's DataTraveler Vault Privacy 3.0 (DTVP 3.0) USB Flash drive provides business-grade security with 256-bit AES hardware-based encryption using XTS block cipher mode, which offers stronger protection than CBC and ECB modes. Kingston DTVP3.0 USB drives are also FIPS 197 validated.

It protects 100% of data stored and enforces complex password protection with minimum characteristics to prevent unauthorised access. For additional peace of mind, the drive locks down and reformats after 10 intrusion attempts. It also features a read-only access mode to avoid potential malware risks.

There has been a series of cases where confidential information has been lost or stolen. If you lose a standard USB stick, any data is easily & instantly available to the finder of the device. However, if your data is on the Kingston Technology DTVP30 - it's safe! 

With GDPR coming soon - mobile data security is something to give serious consideration to!


Further information at: www.kingston.com
Buy from: www.amazon.co.uk

27 April 2018

Microsoft 365 Business - achieve more together


Join this webcast to see a demo of Microsoft 365 Business. Now, for the first time, Microsoft is offering an integrated solution for your business that helps you achieve more together, anywhere it matters with always-on security.

In this demo, you will:
Discover an integrated solution powered by Office 365 and Windows 10, designed for small and mid-size businesses.
Learn how you can connect with your remote coworkers and work on a document in real-time using Word, Outlook, OneDrive, and Skype for Business.
See how inking in Windows 10 enables you to take notes with OneNote.
Learn how you can easily set-up policies to protect company data across devices with Microsoft 365 Business.

Speak with Donline to find out how Microsoft Office 365 can bring benefits to your business & assist with GDPR compliance.


19 July 2022

Denmark bans Chromebooks and Google Workspace in schools over data transfer risks

 

Denmark is effectively banning Google’s services in schools, after officials in the municipality of Helsingør were last year ordered to carry out a risk assessment around the processing of personal data by Google.

In a verdict published last week, Denmark’s data protection agency, Datatilsynet, revealed that data processing involving students using Google’s cloud-based Workspace software suite — which includes Gmail, Google Docs, Calendar and Google Drive — “does not meet the requirements” of the European Union’s GDPR data privacy regulations.

Specifically, the authority found that the data processor agreement — or Google’s terms and conditions —  seemingly allow for data to be transferred to other countries for the purpose of providing support, even though the data is ordinarily stored in one of Google’s EU data centres.

Google’s Chromebook laptops, and by extension Google Workspace, are used in schools across Denmark. But Datatilsynet focused specifically on Helsingør for the risk assessment after the municipality reported a “breach of personal data security” back in 2020. While this latest ruling technically only applies to schools in Helsingør for now, Datatilsynet notes that many of the conclusions it has reached will “probably apply to other municipalities” that use Google Chromebooks and Workspace. It added that it expects these other municipalities “to take relevant steps” off the back of the decision it reached in Helsingør.

The ban is effective immediately, but Helsingør has until August 3 to delete user data.

www.techcrunch.com


25 April 2018

GDPR - a contractual basis to process PII data


Contract
You can rely on this lawful basis if you need to process someone’s personal data:
to fulfil your contractual obligations to them; 
or
because they have asked you to do something before entering into a contract (eg provide a quote).

The processing must be necessary. If you could reasonably do what they want without processing their personal data, this basis will not apply.

You should document your decision to rely on this lawful basis and ensure that you can justify your reasoning.


17 April 2018

The need for a new approach to information protection


Businesses used to need just a firewall to protect sensitive data. But, in a world of cloud and bring-your-own-device (BYOD), a firewall is the just the tip of the iceberg when it comes to security.

Here’s 10 astonishing data trends that highlight the need for a new approach to information protection. Not to mention GDPR!