<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GDPR  and Data Privacy compliance in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GDPR-and-Data-Privacy-compliance/m-p/48238#M1383</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We see there are some security and privacy consumer products in the market like Dark Web Monitoring, Credit Monitoring products, Social Media Monitoring products, Identity Theft Preventing Systems etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oftentimes, for all these products and services- security product offering companies outsourcing with few other third party threat intelligence companies like 4IQ, TRAPX etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have noticed Company X shares PII /PCT-DSS data of their customers with their TP partners and outsourced companies, of course with customer consent to provide the service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it fall under any other GDPR (let's say this is a global product offering)? What precautions should be taken from the product offering company point of view?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For instance if company X shares all the profile pictures of it's customers with a TP Threat intelligence company to identify&amp;nbsp;impersonators or fake accounts, does it pose any threat to Company X from privacy and data protection compliance or legal obligation point of view?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your suggestions and thoughts much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Nov 2021 11:01:28 GMT</pubDate>
    <dc:creator>iluom</dc:creator>
    <dc:date>2021-11-09T11:01:28Z</dc:date>
    <item>
      <title>GDPR  and Data Privacy compliance</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-and-Data-Privacy-compliance/m-p/48238#M1383</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We see there are some security and privacy consumer products in the market like Dark Web Monitoring, Credit Monitoring products, Social Media Monitoring products, Identity Theft Preventing Systems etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oftentimes, for all these products and services- security product offering companies outsourcing with few other third party threat intelligence companies like 4IQ, TRAPX etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have noticed Company X shares PII /PCT-DSS data of their customers with their TP partners and outsourced companies, of course with customer consent to provide the service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it fall under any other GDPR (let's say this is a global product offering)? What precautions should be taken from the product offering company point of view?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For instance if company X shares all the profile pictures of it's customers with a TP Threat intelligence company to identify&amp;nbsp;impersonators or fake accounts, does it pose any threat to Company X from privacy and data protection compliance or legal obligation point of view?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your suggestions and thoughts much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 11:01:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-and-Data-Privacy-compliance/m-p/48238#M1383</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2021-11-09T11:01:28Z</dc:date>
    </item>
  </channel>
</rss>

