GDPR Security Post-Mortems: 10 Critical Lessons You Can Apply Now

Logo
Presented by

Scott M. Giordano, V.P. and Sr. Counsel, Privacy and Compliance, Spirion

About this talk

Since EU supervisory authorities began GDPR enforcement in May 2018, at least 250 companies and government agencies have been punished for privacy and security failures. These failures have resulted in excess of €150M in fines, plus orders for remediation. Remarkably, only a few GDPR articles "such as Articles 5 (Principles), 6 (Legal Basis) and 32 (Security) "are consistently cited by those authorities. Moreover, in the majority of cases, the failures were attributable to basic privacy and security practices. In this presentation, a data protection industry veteran will review several post-mortems, determine what went wrong, and discuss the implications for complying with the privacy and security requirements of the GDPR going forward. Learning objectives: 1. Understand what regulators consider when issuing a GDPR-related penalty. 2. Prioritize remediation efforts, especially in light of the new privacy standard, ISO 27701. 3. Apply these lessons for California Consumer Privacy Act (CCPA) compliance.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (107)
Subscribers (21199)
(ISC)² Security Congress channel contains digital content of activities at (ISC)2's Flagship conference event. You'll find keynotes, sessions and related items.