<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Relevance of GDPR for lots of organisations in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3922#M115</link>
    <description>&lt;P&gt;Is the organization able to demonstrate that there is no personal data? Please note that personal data under EU law is quite broad, and is broader than the scope of "personally identifiable information".&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2017 23:58:34 GMT</pubDate>
    <dc:creator>planois</dc:creator>
    <dc:date>2017-11-26T23:58:34Z</dc:date>
    <item>
      <title>Relevance of GDPR for lots of organisations</title>
      <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3541#M82</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I often get the following question from my customers.&lt;/P&gt;&lt;P&gt;As many organisations, they are handling lot of orders documents, coming from lot of different customers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As such, their "core activities", as defined in the GDPR,&amp;nbsp;are not about "processing personal data", but they are still processing confidential information that potentially contain personal data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you handle this&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;Are they systematically subject to GDPR ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Thierry&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 14:57:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3541#M82</guid>
      <dc:creator>ThierryN</dc:creator>
      <dc:date>2017-11-14T14:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Relevance of GDPR for lots of organisations</title>
      <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3547#M83</link>
      <description>&lt;P&gt;Hello Thierry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without knowing other details relating to the circumstances as you have described, "...processing confidential information that potentially contain personal data..." will&amp;nbsp;be subjected&amp;nbsp;under the GDPR obligations&amp;nbsp;unless it is absolute that the data processed is unable to relate to an individual.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 15:35:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3547#M83</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-14T15:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Relevance of GDPR for lots of organisations</title>
      <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3780#M99</link>
      <description>&lt;P&gt;My view on the quick answer is if as controllers a company(or organisation)&amp;nbsp;collects Personal Data, then it's up to the controller to map it's flows and see what they do with it - this postlet for ITG is a good rule of thumb I feel:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.itgovernance.co.uk/blog/gdpr-how-the-definition-of-personal-data-will-change/" target="_blank"&gt;https://www.itgovernance.co.uk/blog/gdpr-how-the-definition-of-personal-data-will-change/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would focus on their collection, notification and &amp;nbsp;processing activities first as they probably gives the best feel of what they are doing and why. I feel they need a proper inventory of Personal Data to begin to make any calls, nd these should be under the advisement of a properly qualified privacy lawyer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 14:16:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3780#M99</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-11-20T14:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Relevance of GDPR for lots of organisations</title>
      <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3893#M112</link>
      <description>&lt;P&gt;If that order data identifies (or relates to) real people in the EU, it would be difficult to escape the conclusion that GDPR applies, unless they claim one of the exceptions in Article 2:&amp;nbsp;&lt;A href="http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN" target="_blank"&gt;http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;amp;from=EN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The wording about "core activities" comes from Article 37, which is about Data Protection Officers. Perhaps the organisation could argue that they don't need a DPO - but the organisation would still have to satisfy GDPR.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 16:18:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3893#M112</guid>
      <dc:creator>bobrayner</dc:creator>
      <dc:date>2017-11-26T16:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Relevance of GDPR for lots of organisations</title>
      <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3916#M113</link>
      <description>&lt;P&gt;Observing the&amp;nbsp;past trends, regulators and consumers will expect organizations to have a high burden under&amp;nbsp;GDPR or EU Data Protection Directive&amp;nbsp;to prove that the exceptions at Article 2 apply to them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Demonstrating accountability is a new norm in data protection compliance. WP29, the impending Europe Data Protection Board (EDPB) through its proposed guidelines, has encouraged organisations to designate DPO voluntarily even though Article 37 may not apply to them. While the organisations have determined their activities may not be 'core', they are still expected to demonstrate compliance under Article 3 of the GDPR&amp;nbsp;where the processing of personal data in the context of the activities of an establishment of a controller or a processor in&amp;nbsp;EU regardless of whether the processing takes place in the Union or not.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 23:21:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3916#M113</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-11-26T23:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Relevance of GDPR for lots of organisations</title>
      <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3922#M115</link>
      <description>&lt;P&gt;Is the organization able to demonstrate that there is no personal data? Please note that personal data under EU law is quite broad, and is broader than the scope of "personally identifiable information".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 23:58:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3922#M115</guid>
      <dc:creator>planois</dc:creator>
      <dc:date>2017-11-26T23:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Relevance of GDPR for lots of organisations</title>
      <link>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3949#M123</link>
      <description>&lt;P&gt;It's very unlikely that an organisation could prove that &lt;STRONG&gt;none&lt;/STRONG&gt; of their order data is personal data. Even if orders are strictly B2B, the order data probably refers to an account manager, or a recipient, or the details of who signed off the requirement/spend, or something else like that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the 21st century it's very hard to run an IT service which tracks product or services sold to people, whilst pretending that you know &lt;EM&gt;nothing&lt;/EM&gt; about those people - not even their name or address or Paypal account or their service preferences. It could still work for old-fashioned face-to-face business where you know nothing about the random person who just appeared in your shop, but in that case the IT footprint is minimal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 14:33:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Relevance-of-GDPR-for-lots-of-organisations/m-p/3949#M123</guid>
      <dc:creator>bobrayner</dc:creator>
      <dc:date>2017-11-27T14:33:06Z</dc:date>
    </item>
  </channel>
</rss>

