<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Your Top 5? - GDPR in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3812#M106</link>
    <description>&lt;P&gt;You have rightfully pointed out, Early_Adopter,&amp;nbsp;"...&amp;nbsp; don't call your DPO a DPO, unless you are mandated to have one under GDPR or other frameworks as there might be a heavier burden of expectation...". The role is a compliance role rather than a risk management function. An IT Manager is more of a risk management or operation role and does not have a legal mandate like the DPO has&amp;nbsp;under GDPR. It creates conflict of interest due to its operative nature as demonstrated in the German authority's opinion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While you will find others like Singapore embedded DPO in its data protection regulatory rules back in 2014 and not as loudly as GDPR demands, Hong Kong continues advocating the role as a best practice and South Korea as well as Philippines have revised their regulations to accommodate&amp;nbsp;the data protection role legally without&amp;nbsp;mentioning DPO directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With GDPR being so descriptive and likely to set a 'gold' standard for the role, we will find these is likely to create a norm or&amp;nbsp;increase expectations&amp;nbsp;for the regulatory environment across the globe in years to come.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2017 12:59:51 GMT</pubDate>
    <dc:creator>flyingboy</dc:creator>
    <dc:date>2017-11-21T12:59:51Z</dc:date>
    <item>
      <title>Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3606#M84</link>
      <description>&lt;P&gt;What are your personal 'Top 5' practical tips for implementing GDPR?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. &lt;STRONG&gt;Remember that the fundamental purpose of GDPR is to PROTECT&amp;nbsp;the personal data and rights of individual Data Subjects&lt;/STRONG&gt;: It's the "General Data *Protection* Regulation. (This sounds obvious but is sometimes forgotten!)&lt;/P&gt;&lt;P&gt;2. &lt;STRONG&gt;Prioritise security awareness&amp;nbsp;-&amp;nbsp;&lt;/STRONG&gt;don't leave it as an afterthought for your annual compliance "refresher" training!&amp;nbsp;&lt;SPAN&gt;As soon as possible&amp;nbsp;in the GDPR implementation, start training staff (eg Senior Managers, Project Managers and Security staff) to recognise typical examples of 'personal data' such as different types of personal unique identifiers, data that uniquely identfies an individual because they are the only person who has that Job Title, etc. Also, to always *consider* the extent to which personal data&amp;nbsp;could be involved, from the outset of any project. (Broad statements such as:"There's no personal data involved in this project" usually require further investigation.) Aim to have all your staff trained to understand the Principles and the key Definitions that apply to their own roles by May 25 2018.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4. Unless you are authorised to do so, &lt;STRONG&gt;don't try to 'interpret' the meaning of any aspect of GDPR&lt;/STRONG&gt; - check the meaning and its implications with your Data Protection Officer or other authorised data protection/privacy/legal lead.&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. &lt;STRONG&gt;The 'special categories' of personal data&lt;/STRONG&gt; (broadly similar to 'sensitive personal data' under current EU legislation) &lt;STRONG&gt;require ADDITIONAL protection&lt;/STRONG&gt; on top of any controls that&amp;nbsp;will apply to 'personal data'. Security staff are well-placed to advise on "additional protection" - eg&amp;nbsp;data classification, data handling and other data 'processing' requirements.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 02:32:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3606#M84</guid>
      <dc:creator>SeaCISSP</dc:creator>
      <dc:date>2017-11-15T02:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3607#M85</link>
      <description>&lt;P&gt;.... I deleted&amp;nbsp;Number 3!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Ensure your organisation&amp;nbsp;&lt;STRONG&gt;understands the full implications of the Data Controller and Data Processor responsibilities&lt;/STRONG&gt;. For instance, Data Controllers have to provide clear instructions to enable their Data Processors to process the personal data entrusted to them securely and with confidence. Data Processors must do likewise if they are allowed to sub-contract any elements of the personal data processing to their own suppliers. This presupposes that everyone will have complete and up-to-date contractual records that easily identify who the Data Processors are and that the communication channels between DCs and their DPs are straightforward and kept up-to-date ....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 01:32:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3607#M85</guid>
      <dc:creator>SeaCISSP</dc:creator>
      <dc:date>2017-11-15T01:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3609#M86</link>
      <description>&lt;P&gt;Rather than focusing 'Top 5 practical tips for implementing GDPR', I suggest:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Recognise one size does not fit all – consider the level of risk/harm&lt;/LI&gt;&lt;LI&gt;Assign clearly defined roles for all stages (both internally and externally to&amp;nbsp;the organisation)&lt;/LI&gt;&lt;LI&gt;Identify&amp;nbsp;an Executive “Champion” or Sponsor if there is none at Broad or the highest management level&lt;/LI&gt;&lt;LI&gt;Build a robust process with scalability in mind&lt;/LI&gt;&lt;LI&gt;Communicate and reinforce training at every opportunity&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 01:52:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3609#M86</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-15T01:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3610#M87</link>
      <description>&lt;P&gt;Hi Flyingboy. Thank you for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sure, organisations have to have robust high-level GRC measures and so on and strongly agree there needs to be an executive sponsor. These are all things that a good security professional should already be aware of.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggested 'practical' tips to highlight some of the simple basic details which can easily get overlooked or which people may not have come across yet, if they haven't implemented data protection and privacy measures before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, just hoping to learn more about 'what personally works' for everyone - there are no 'right or wrong ' answers!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 02:09:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3610#M87</guid>
      <dc:creator>SeaCISSP</dc:creator>
      <dc:date>2017-11-15T02:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3611#M88</link>
      <description>&lt;P&gt;Hello AnnaC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Awareness is one thing, however implementation is&amp;nbsp;another. Sometimes, keeping simple is needed to get the message across. If you are looking for more detailed implementations, you are unlikely to find&amp;nbsp;them within our few short posts - remember my first recommendation - (Recognise one size does not fit all – consider the level of risk/harm). Every organisations or individuals (even for&amp;nbsp;security or privacy professionals) are different or have different circumstances when handling data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are looking for something specific, you can reach out to&amp;nbsp;me directly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 02:34:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3611#M88</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-15T02:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3619#M90</link>
      <description>&lt;P&gt;1. GDPR is a Good Thing so be positive about it within your organisation.&amp;nbsp; Don't treat it as a tick box exercise or, as I heard someone describe it last week, 'a Great Depressing Pile of Regulation'.&amp;nbsp; It is something we should all be doing anyway.&lt;/P&gt;&lt;P&gt;2. Sort out the basics first.&amp;nbsp; Be sure of your processing activities, legal bases for processing and purposes.&amp;nbsp; I've found that making sure those are rock solid is very helpful as what follows can be looked upon as a bit of an uphill climb.&amp;nbsp; That's a lot more palatable if you have established a solid base camp.&lt;/P&gt;&lt;P&gt;3. Get legal advice.&amp;nbsp; I am not a lawyer.&amp;nbsp; There is no magic compliance checklist.&amp;nbsp; I am a CISSP so have signed a code of ethics that includes not pretending I know everything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. Don't assume your only communication path is upwards.&amp;nbsp; While it's important to make sure you get buy-in from the Board, your weak spots will probably lie elsewhere so a comms and awareness raising plan should be inclusive. Trying to strike a balance between shock and awe (we're going to get fined 20m euros) and boring people half to death with yet another reference to GDPR is difficult but not impossible&lt;/P&gt;&lt;P&gt;5. Don't panic&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 14:20:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3619#M90</guid>
      <dc:creator>robertc</dc:creator>
      <dc:date>2017-11-15T14:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3740#M92</link>
      <description>&lt;P&gt;Here's my top five practical, biased and limited thoughts - not comprehensive, caveat emptor, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&lt;STRONG&gt;Download the Law - read it, if nothing else it's a&amp;nbsp;formidable work of legal minds&lt;/STRONG&gt;, also read a few of the legal company references, the new e&lt;SPAN&gt;-Privacy Regulation&amp;nbsp;&lt;/SPAN&gt;and look at the WP29 opinions. Lastly with GDPR make sure your DPO/General Counsel doesn't forget the APEC Privacy Framework and all the other national privacy regulations that apply to you, your privacy program will have better longevity and be less brittle if it's addressing the broad issues. &amp;nbsp;&lt;/P&gt;&lt;P&gt;2. &lt;STRONG&gt;Look at sending your guys&amp;nbsp;on&amp;nbsp;courses with IAPP(DPO Ready) and ITGovenance(GDPR F/P)&lt;/STRONG&gt; - I've attended&amp;nbsp;both and would say that IAPP offers more for the top end of town, whilst ITGovernance is interesting from a practitioner's standpoint. Both sets of training have value, there may also be others. Once they are trained, please share. If not build your own training program.&lt;/P&gt;&lt;P&gt;3.&lt;STRONG&gt;Get your privacy terms of reference defined and promulgated in your company/organization in a jargon busting way&lt;/STRONG&gt;. Should I Gap Analyze my PIMS when set against my PIA or ensure that i practice PDB on my BCRs so they harmonize my Model Contracts? It will only be clear what the team knows what it all means, when this is done - if you are exposed, and you probably are then a CEO email linking the resource and emphasizing his/her commitment really helps.&lt;/P&gt;&lt;P&gt;4.&lt;STRONG&gt;Do your data mapping&lt;/STRONG&gt;, focus on what is processed in priority order and take the elements of personal data you have (and because the is the ISC2) work with your friendly DLP, tagging, complince and monitoring guys to help. Security tools can't do all, or even most of the work but I feel they can really help look for spills. Focus them on the live processing first, before you try to boil the ocean crawling your databases and file stores;&lt;/P&gt;&lt;P&gt;5. &lt;STRONG&gt;Avoid, or dial down the weight of opinions of those offering certainty&lt;/STRONG&gt;, there is as yet no GDPR case law as yet so we're really not sure what will happen - maybe it will be like just like&amp;nbsp;Benny Hill,&amp;nbsp;with all the supervisory authorities chasing Google, Facebook and Microsoft... and,&amp;nbsp;hilarity ensues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 18:50:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3740#M92</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-11-17T18:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3773#M97</link>
      <description>&lt;P&gt;Hi Early_Adopter. Great post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you say, there is no case law for GDPR as yet and some organisations appear to be adopting a 'wait and see'/'let's stay under the radar' approach as a result of this. This may be a short-sighted approach, in particular for organisations that have resided in the EU for some time and are already subject to the decades-long privacy legislation that pre-dates GDPR.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although there is no 'certainty' as yet, there are privacy legislative precedents and "history" to refer to and learn from. The EU's privacy community (eg Courts, Regulators, DPOs and other long-standing Data Protection Practitioners) will not regard GDPR as "new" or a completely fresh start with a level playing field. To them, GDPR is at least the "second wave" of privacy legislation,&amp;nbsp;with the latest&amp;nbsp;changes constituting about 30% of the Regulation and including carefully-worded clauses that address some of the problematic grey areas and potential legal loopholes that arose in the past.&amp;nbsp;The responses to other GDPR changes, such as those associated with new technology, will be less predictable, leaving more opportunities for&amp;nbsp; interpretation and challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From a risk perspective, perhaps the most volatile and unpredictable aspects of GDPR in the long run will be associated with the world's political climate and fluctuating attitudes to privacy as a fundamental right. We shall see!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 11:51:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3773#M97</guid>
      <dc:creator>SeaCISSP</dc:creator>
      <dc:date>2017-11-20T11:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3779#M98</link>
      <description>&lt;P&gt;Absolutely agree with you - just because there is no case law for GDPR only adds to uncertainty in rulings - 'how much will it hurt...maybe I can get away..?' Is in my view a going out of business model.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wait and see is really going to hurt if you have a breach or a supervisory authority comes calling &amp;nbsp;can't prove you had considered the principles, privacy by design/default, legitimate grounds for transfer, hired a DPO, inventoried/mapped personal data and implemented 'appropriate technical and organizational controls', etc...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just under thirty supervisory authorities all with slightly different goals and agendas an all wanting success won't make for a slow roll out IMHO.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 14:06:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3779#M98</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-11-20T14:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3798#M100</link>
      <description>&lt;P&gt;Hello Both,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even though there&amp;nbsp;is no case law&amp;nbsp;mentioned GDPR directly, there are court decisions started referencing some&amp;nbsp;GDPR&amp;nbsp;approaches:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Right to be forgotten (RTBF) - Google&lt;/LI&gt;&lt;LI&gt;CJEU&amp;nbsp;concluded recently&amp;nbsp;that dynamic IP addresses are personal data while the current EU Data Protection Directive or national laws have not considered specifically - Breyer&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Let's work towards compliance and do not allow opportunities for regulators to make an example of us.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 03:17:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3798#M100</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-21T03:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3801#M103</link>
      <description>&lt;P&gt;Agreed, we know the velocity of the decisions in the EU, and Germany in particular is pretty good example of how strong it could be with their Federal Data Protection Act:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://iapp.org/media/pdf/resource_center/Eng-trans-Germany-DPL.pdf" target="_self"&gt;https://iapp.org/media/pdf/resource_center/Eng-trans-Germany-DPL.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For a great round-up of the pre-existing(non-GDPR) case law I recommend taking a look at this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://ec.europa.eu/anti-fraud/sites/antifraud/files/caselaw_2001_2015_en.pdf" target="_self"&gt;https://ec.europa.eu/anti-fraud/sites/antifraud/files/caselaw_2001_2015_en.pdf&lt;/A&gt; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 04:42:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3801#M103</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-11-21T04:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3803#M104</link>
      <description>&lt;P&gt;While&amp;nbsp;you have mentioned&amp;nbsp;Germany, it helps to remind me of another regulator's decision on Data Protection Officer&amp;nbsp;(DPO)&amp;nbsp;aligning with Article 37, 38 and 39 under the GDPR during late 2016 while referencing the FDPA:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://blogs.orrick.com/trustanchor/2016/12/01/data-protection-officer-and-it-manager-two-jobs-that-do-not-match/" target="_blank"&gt;https://blogs.orrick.com/trustanchor/2016/12/01/data-protection-officer-and-it-manager-two-jobs-that-do-not-match/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 05:36:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3803#M104</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-21T05:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3811#M105</link>
      <description>&lt;P&gt;Totally, that's a no brainer on a conflict of interest, plus a IT Manager does not reach anywhere high enough in the organisation. From the link you referenced:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;V. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Recommendation&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Companies required to appoint a DPO are thus well advised to carefully consider candidates that are free from conflicts of interest. While it does not appear necessary to preclude a DPO from having other corporate functions, the designated individual should not be in charge of, or have a personal stake in, significant decision-making relating to IT. One potential solution may be to “firewall” DPOs from such decision-making processes. Suffice it to say that this aspect of GDPR/BDSG compliance will be scrutinized heavily by German (and likely other) data protection authorities in the coming months and years.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DPOs advise this separation, so this is good advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is also a school of thought I've come across that says don't call your DPO a DPO, unless you are mandated to have one under GDPR or other frameworks as there might be a heavier burden of expectation. Not the best reason IMHO, but this was from some lawyers.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 12:03:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3811#M105</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-11-21T12:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3812#M106</link>
      <description>&lt;P&gt;You have rightfully pointed out, Early_Adopter,&amp;nbsp;"...&amp;nbsp; don't call your DPO a DPO, unless you are mandated to have one under GDPR or other frameworks as there might be a heavier burden of expectation...". The role is a compliance role rather than a risk management function. An IT Manager is more of a risk management or operation role and does not have a legal mandate like the DPO has&amp;nbsp;under GDPR. It creates conflict of interest due to its operative nature as demonstrated in the German authority's opinion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While you will find others like Singapore embedded DPO in its data protection regulatory rules back in 2014 and not as loudly as GDPR demands, Hong Kong continues advocating the role as a best practice and South Korea as well as Philippines have revised their regulations to accommodate&amp;nbsp;the data protection role legally without&amp;nbsp;mentioning DPO directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With GDPR being so descriptive and likely to set a 'gold' standard for the role, we will find these is likely to create a norm or&amp;nbsp;increase expectations&amp;nbsp;for the regulatory environment across the globe in years to come.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 12:59:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3812#M106</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-21T12:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3814#M107</link>
      <description>&lt;P&gt;Other than outlaw.com:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.out-law.com/" target="_blank"&gt;https://www.out-law.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;.... Does anyone know of any legal/media sites that are centralising and tracking privacy-related items and court cases?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;('The Register' tracks security news items but it can be quite partisan.)&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 14:50:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3814#M107</guid>
      <dc:creator>SeaCISSP</dc:creator>
      <dc:date>2017-11-21T14:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3815#M108</link>
      <description>&lt;P&gt;Definitely - and there's always the possibility that the organisation 'waiting and seeing' could be the subject of a regulatory investigation or court case itself, privacy data breaches being the far-reaching and sometimes unpredictable things they are.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 14:53:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3815#M108</guid>
      <dc:creator>SeaCISSP</dc:creator>
      <dc:date>2017-11-21T14:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3817#M109</link>
      <description>&lt;P&gt;IAPP has some good jumping off points:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://iapp.org" target="_blank"&gt;https://iapp.org&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 15:37:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3817#M109</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-11-21T15:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3820#M110</link>
      <description>&lt;P&gt;1. Make it cross-department effort, it is not just IT, just Legal, etc.&amp;nbsp; Include Legal, IT, InfoSec, Compliance, perhaps Risk&lt;/P&gt;&lt;P&gt;2. Understand the data-flows and contracts in place - map the data-flows, review the contracts and consent for processing data.&lt;/P&gt;&lt;P&gt;3. Create a process for Privacy Risk Assessment and integrate it into the System Acquisition and Deployment, and Vendor Management processes&lt;/P&gt;&lt;P&gt;4. Implement Records Management practice that will enable the organisation to discover data based on an individual's names or unique identifier.&lt;/P&gt;&lt;P&gt;5. Deploy Threat Detection and Response capability to detect and respond to breaches if they occur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And below are the 5 stages I saw recently&amp;nbsp; in a presentation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DLXd6B5WkAAXnTX.jpg" style="width: 447px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/1734i9CFEEE5C4D018C87/image-dimensions/447x335?v=v2" width="447" height="335" role="button" title="DLXd6B5WkAAXnTX.jpg" alt="DLXd6B5WkAAXnTX.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 15:52:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3820#M110</guid>
      <dc:creator>dnn</dc:creator>
      <dc:date>2017-11-21T15:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3839#M111</link>
      <description>&lt;P&gt;While I am unsure of a website that offers a centralised view about privacy tracking or court cases, I find this&amp;nbsp;article quite useful if you&amp;nbsp; like to know the data protection or privacy enforcement actions taken across the globe, not just EU:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.lexology.com/library/detail.aspx?g=4ba24232-056e-4a6a-8e4a-1d76a0300105&amp;amp;utm_source=lexology+daily+newsfeed&amp;amp;utm_medium=html+email+-+body+-+general+section&amp;amp;utm_campaign=lexology+subscriber+daily+feed&amp;amp;utm_content=lexology+daily+newsfeed+2017-11-22&amp;amp;utm_term=" target="_blank"&gt;https://www.lexology.com/library/detail.aspx?g=4ba24232-056e-4a6a-8e4a-1d76a0300105&amp;amp;utm_source=lexology+daily+newsfeed&amp;amp;utm_medium=html+email+-+body+-+general+section&amp;amp;utm_campaign=lexology+subscriber+daily+feed&amp;amp;utm_content=lexology+daily+newsfeed+2017-11-22&amp;amp;utm_term=&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 11:46:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3839#M111</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-22T11:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Your Top 5? - GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3924#M117</link>
      <description>&lt;P&gt;My number 6 would be don't be taken in by the snakeoil salesmen punting GDPR certification &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 00:26:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Your-Top-5-GDPR/m-p/3924#M117</guid>
      <dc:creator>robertc</dc:creator>
      <dc:date>2017-11-27T00:26:31Z</dc:date>
    </item>
  </channel>
</rss>

