goed voorbereid op privacy

37
Draft for discussion purposes only

Upload: nederlandse-beroepsorganisatie-van-accountants

Post on 07-Jul-2015

114 views

Category:

Technology


0 download

DESCRIPTION

Presentatie 'Goed voorbereid op privacy' door Annika Sponselee en Rob Muris.

TRANSCRIPT

Page 1: Goed voorbereid op privacy

Draft for discussion purposes only

Page 2: Goed voorbereid op privacy

Draft for discussion purposes only

Page 3: Goed voorbereid op privacy

Draft for discussion purposes only

Page 4: Goed voorbereid op privacy

Draft for discussion purposes only

Page 5: Goed voorbereid op privacy

Draft for discussion purposes only

Page 6: Goed voorbereid op privacy

Draft for discussion purposes only

Page 7: Goed voorbereid op privacy

Rapid technological developments that led to jeopardizing privacy

1950

European Convention on Human Rights

1995

Need for regulation:

European General Privacy Directive (95/46/EC)

2001

Dutch Personal Data Protection Act

2012

Proposal for a new EU regulation

Equal level of personal data protection

in all EU Member States

Draft for discussion purposes only

Page 8: Goed voorbereid op privacy

Draft for discussion purposes only

Page 9: Goed voorbereid op privacy

A legal ground for

processing of Personal Data

must exist

Obligation to implement

technical and organisational

measures in order to secure

Personal Data

Applicable retention periods

regarding Personal Data

Obligation to inform data

subjects

Additional requirements apply

when transferring Personal

Data outside the EU

A data processing

agreement between parties

needs to be in place

Obligation to notify the

AuthoritiesData subject rights

Personal data shall be

collected for specific,

explicitly defined and

legitimate purposes

Draft for discussion purposes only

Page 10: Goed voorbereid op privacy

•–

•–

•–

•–

•–

•–

Draft for discussion purposes only

Page 11: Goed voorbereid op privacy

Draft for discussion purposes only

Page 12: Goed voorbereid op privacy

Brand Risk

• Branding and

positioning

• Risk to brand from

privacy breach

• Potential

inconsistencies

between policies

and practices

• Employee privacy in

multinational companies

• Requires localized and tailored

approach

• Multiple

jurisdictions

of privacy regulations

• Country specific compliance

• Legal solutions for EU data

transfers such as Safe

Harbor or model contracts

• Industry specific privacy codes of

conduct Employee

Data Mgmt

Increased

Regulation

Customer

/Student

Sensitivity

• Sensitivity to aggressive

marketing practices

• Existing privacy policies

and client expectations

• Differing perspectives and

expectations

• Procedures for

responding to privacy

complaints

• Relationships with partners,

vendors and service providers

• Inconsistent implementation of

privacy practices among

independent organizations

• Who has responsibility

and associated

liability for privacy?

• Web-based e-commerce

applications interact with

clients online

• Use of personalization

technologies such as

cookies, smart tags, unique

identifiers, client profiles,

etc.

• Information exchange

economy

• CRM and HRIS

systems centralizes client and

employee data from around

the world

Globalization

Advances in

Technology

Extended

Enterprise

Draft for discussion purposes only

Page 13: Goed voorbereid op privacy

Business needs

• Direct and viral marketing

initiatives

• Centralized vs. decentralized

databases (ERP, CRM, Legacy)

• Data mining and business

intelligence

• Replication and synchronization

of information

• Personalized

client/student/employee

experiences

Privacy Requirements

• Processed fairly and lawfully

• Collected for specific, explicit, and

legitimate purposes

• Adequate, relevant, and not

excessive

• Accurate and secure

• Not kept longer than necessary

• Processed in accordance with

data subject’s rights

• Not transferred to countries with

inadequate protection

Draft for discussion purposes only

Page 14: Goed voorbereid op privacy

© 2012 Deloitte The Netherlands

Risk Assessment

Metrics and Reporting

Technology Procedures

Strategy

Policies

AuditAnd Compliance

EvaluationAnd Adjustment

Organization

Communications,

Training, Awareness

Draft for discussion purposes only

Page 15: Goed voorbereid op privacy

Draft for discussion purposes only

Page 17: Goed voorbereid op privacy

Draft for discussion purposes only

Page 18: Goed voorbereid op privacy

Draft for discussion purposes only

Page 19: Goed voorbereid op privacy

Deloitte Digital

Draft for discussion purposes only

Page 20: Goed voorbereid op privacy

Draft for discussion purposes only

Page 21: Goed voorbereid op privacy

Draft for discussion purposes only

Page 22: Goed voorbereid op privacy

Deloitte Digital

Draft for discussion purposes only

Page 23: Goed voorbereid op privacy

Deloitte Digital

Draft for discussion purposes only

Page 24: Goed voorbereid op privacy

Deloitte Digital

Draft for discussion purposes only

Page 25: Goed voorbereid op privacy

Deloitte Digital

Draft for discussion purposes only

Page 26: Goed voorbereid op privacy

Deloitte Digital

Draft for discussion purposes only

Page 27: Goed voorbereid op privacy

Draft for discussion purposes only

Page 28: Goed voorbereid op privacy

Draft for discussion purposes only

Page 29: Goed voorbereid op privacy

Deloitte Digital

Draft for discussion purposes only

Page 30: Goed voorbereid op privacy

Draft for discussion purposes only

Page 31: Goed voorbereid op privacy

Can I alter guess other accounts?

What are the other account numbers?

What else can be uploaded?

What if I alter this number?

Can I access administrator pages?

Can transaction be manipulated?

Draft for discussion purposes only

Page 32: Goed voorbereid op privacy

Deloitte Digital

Page 33: Goed voorbereid op privacy

Draft for discussion purposes only

Page 34: Goed voorbereid op privacy

Draft for discussion purposes only

Page 35: Goed voorbereid op privacy

Deloitte Digital

Annika Sponselee

Senior Manager

[email protected]

+31 (0) 6 1099 9302

Rob Muris

Senior Consultant

[email protected]

+31 (0) 6 1099 9133

Draft for discussion purposes only

Page 36: Goed voorbereid op privacy

Draft for discussion purposes only

Page 37: Goed voorbereid op privacy