Data Protection (GDPR) Workshop English English

day 1

GDPR: In Practice

    • GDPR in field of information security and data protection
    • GDPR vs export regulations, IP and industry standards (ISO, PCI-DSS etc.)
    • Territorial scope
    • Controlling and processing
    • Categories of personal data + Cookie
    • Open data, public data
Data protection and information security workshop GDPR In Practice illustration

GDPR: Basis

    • Data subject
    • Controller (natural person, business reason, authorities)
    • Processors
    • Joint controllers
    • Purpose of personal data processing, purpose limitation
    • Data minimisation, transparency vs stockpiling data
    • Data protection by design
Data protection and information security workshop GDPR Basis illustration

GDPR: Lawfulness of Processing

    • Consent, opt-in (silence is not consent)
    • Processing is necessary for the performance of a contract
    • Legal obligation
    • Legitimate interests of a controller or third party (impact assessment, risk evaluation)
    • To protect the vital interests of a natural person
    • Public interest or in the exercise of official authority
Data protection and information security workshop GDPR Lawfulness of Processing illustration

GDPR: Rights of Data Subjects

    • Communication, Notification obligation
    • Right of access by the data subject
    • Right to rectification
    • Right to erasure (right to be forgotten)
    • Right to restriction of processing
    • Right to data portability
    • Right to object
Data protection and information security workshop GDPR Rights of Data Subjects illustration
day 2

GDPR: Administration Activities of Data processing

    • Automated decision-making, including profiling
    • Contracts
    • Data transfer of personal data to third party, countries or international organisations
    • Export regulations
    • Expiration
    • Privacy Notice, Policy Policy, Binding Corporate Rules
Data protection and information security workshop GDPR Administration Activities illustration

GDPR: Ascpects of Using of Personal Data

    • Codes of conduct, certification
    • Confidentiality, integrity
    • Anonymous information, pseudonymisation
    • What, Where, Whom, Why, Till when, Which form?
Data protection and information security workshop GDPR Using of Personal Data illustration

GDPR: Complaint and Possible Outcomes

    • Controller's representative
    • Data Protection Officer (when to designate a DPO?)
    • Supervisory authority
    • Court
    • Compensation
    • Incident (reporting: when and how?)
    • Fines: Max. 20 000 000 EUR, or 4% of the total worldwide annual turnover!
Data protection and information security workshop GDPR Complaint and Possible Outcomes illustration

GDPR: IT Data Protection Requirements

    • Limiting authorisations, least privilege principle
    • Strong passwords, multi factor authentication
    • Encryption (file, connection, VPN etc.)
    • Configuration, virus and firewall protection
    • Patching of assests and softwares
    • Logging
    • Penetration testing, Audit, controll
Data protection and information security workshop GDPR: Data Protection Requirements illustration
day 3

GDPR: Data Processing In Workplace

    • Documents of employee and CVs of job seekers
    • Copying personal IDs
    • Health data, certificate of criminal record
    • Personal data related to private life
    • Photos
    • Biometric data, chips
    • Transferring employee data
Data protection and information security workshop GDPR: Processing of Data in Workplace illustration

GDPR: Controlling Employee

    • Alcohol and drug test
    • Search employee's bag
    • Tracking, monitoring employee, spying on employee, candid camera observation
    • Related regulations
Data protection and information security workshop GDPR: Controlling Employee illustration

GDPR: Marketing

    • DM
    • Opt-in, opt-out (consent and withdraw consent)
    • Robinson list (Mail Preference Service - MPS)
    • Facebook
    • Google
Data protection and information security workshop GDPR: Marketing illustration

GDPR: Business Continuity Principle

    • Encryption of data stored on media (Floppy, CD, DVD, pendrive)
    • Backup
    • High availability and robostness
    • Crisis management
    • Inventories
    • Training, Education
Data protection and information security workshop GDPR: Business Continuity Principle illustration
BAHACO GDPR AI Cloud Ltd.
Address: 1/3 Tulipán utca, Pápa, 8500, Hungary
E-mail: workshop [at] bahaco.hu
Internet: https://www.bahaco.eu
VAT number: 28809355-2-19
Companies Court Nr.: 19-09-521486
Logo
Workshop