| day 1 | 
| GDPR: In PracticeGDPR in field of information security and data protectionGDPR vs export regulations, IP and industry standards (ISO, PCI-DSS etc.)Territorial scopeControlling and processingCategories of personal data + CookieOpen data, public data
 |  | 
| GDPR: BasisData subjectController (natural person, business reason, authorities)ProcessorsJoint controllersPurpose of personal data processing, purpose limitationData minimisation, transparency vs  stockpiling dataData protection by design
 |  | 
| GDPR: Lawfulness of ProcessingConsent, opt-in (silence is not consent)Processing is necessary for the performance of a contractLegal obligationLegitimate interests of a controller or third party (impact assessment, risk evaluation)To protect the vital interests of a natural personPublic interest or in the exercise of official authority
 |  | 
| GDPR: Rights of Data SubjectsCommunication, Notification obligationRight of access by the data subjectRight to rectificationRight to erasure (right to be forgotten)Right to restriction of processingRight to data portabilityRight to object
 |  | 
| day 2 | 
| GDPR: Administration Activities of Data processingAutomated decision-making, including profilingContractsData transfer of personal data to third party, countries or international organisationsExport regulationsExpirationPrivacy Notice, Policy Policy, Binding Corporate Rules
 |  | 
| GDPR: Ascpects of Using of Personal DataCodes of conduct, certificationConfidentiality, integrityAnonymous information, pseudonymisationWhat, Where, Whom, Why, Till when, Which form?
 |  | 
| GDPR: Complaint and Possible OutcomesController's representativeData Protection Officer (when to designate a DPO?)Supervisory authorityCourtCompensationIncident (reporting: when and how?)Fines: Max. 20 000 000 EUR, or 4% of the total worldwide annual turnover!
 |  | 
| GDPR: IT Data Protection RequirementsLimiting authorisations, least privilege principleStrong passwords, multi factor authenticationEncryption (file, connection, VPN etc.)Configuration, virus and firewall protectionPatching of assests and softwaresLoggingPenetration testing, Audit, controll
 |  | 
| day 3 | 
| GDPR: Data Processing In WorkplaceDocuments of employee and CVs of job seekersCopying personal IDsHealth data, certificate of criminal recordPersonal data related to private lifePhotosBiometric data, chipsTransferring employee data
 |  | 
| GDPR: Controlling EmployeeAlcohol and drug testSearch employee's bagTracking, monitoring employee, spying on employee, candid camera observationRelated regulations
 |  | 
| GDPR: MarketingDMOpt-in, opt-out (consent and withdraw consent)Robinson list (Mail Preference Service - MPS)FacebookGoogle
 |  | 
| GDPR: Business Continuity PrincipleEncryption of data stored on media (Floppy, CD, DVD, pendrive)BackupHigh availability and robostness Crisis managementInventoriesTraining, Education
 |  | 
BAHACO GDPR AI Cloud Ltd. Address: 1/3 Tulipán utca, Pápa, 8500, Hungary
 E-mail: workshop [at] bahaco.hu
 Internet: https://www.bahaco.eu
 VAT number: 28809355-2-19
 Companies Court Nr.: 19-09-521486
 |  Workshop
 |