<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GDPR Article 5(2) - Demonstrate compliance ... but how? in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7425#M306</link>
    <description>&lt;P&gt;Basically evidence and documentation of what you are doing and what you are not doing and why&lt;/P&gt;</description>
    <pubDate>Fri, 16 Feb 2018 11:10:40 GMT</pubDate>
    <dc:creator>phollan1</dc:creator>
    <dc:date>2018-02-16T11:10:40Z</dc:date>
    <item>
      <title>GDPR Article 5(2) - Demonstrate compliance ... but how?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7206#M295</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I've been reading the text of the GDPR ... don't laugh, I think it's worth doing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Article 5.2 states "&lt;/SPAN&gt;&lt;SPAN&gt;The controller shall be responsible for, and be able to demonstrate compliance with, paragraph&amp;nbsp;1 (‘accountability’)."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&lt;A href="http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679" target="_blank"&gt;http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&lt;/A&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I get that, and I'm not going to argue it ... but let me ask the stupid question ... how do I actually demonstrate GDPR compliance?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2018 16:57:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7206#M295</guid>
      <dc:creator>Del</dc:creator>
      <dc:date>2018-02-09T16:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Article 5(2) - Demonstrate compliance ... but how?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7210#M297</link>
      <description>&lt;P&gt;This could go on and on, sorry...... so some bits:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The answer is document, document, document... need to be able to show a culture of ‘privacy by design’ and transparency for the data subjects..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security structure which should be from the top.&lt;/P&gt;&lt;P&gt;all information assets what they contain personal information wise.&lt;/P&gt;&lt;P&gt;what legal reasons there are for processing this information (reasons for processing)&lt;/P&gt;&lt;P&gt;carry out privacy impact assessments and risk assess&lt;/P&gt;&lt;P&gt;record information flows, who has access, how and why&lt;/P&gt;&lt;P&gt;all the control measures that are in place, physical, organisational and technical&lt;/P&gt;&lt;P&gt;all the training of staff on data protection&lt;/P&gt;&lt;P&gt;all the contracts with third parties&lt;/P&gt;&lt;P&gt;any information transfers especially to third countries and how that is protected.&lt;/P&gt;&lt;P&gt;all consents and what they consented to and show that it was informed&lt;/P&gt;&lt;P&gt;privacy notices for the data subjects&lt;/P&gt;&lt;P&gt;The breach processes&lt;/P&gt;&lt;P&gt;record retention periods for the information assets&lt;/P&gt;&lt;P&gt;how to handle data subject rights.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will have missed bits off but hopefully you see the idea. &amp;nbsp;After that I think it depends on the type of company, e.g data controller needed or not etc. &amp;nbsp;Other bits like no opt outs on web sites, opt in only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hopefully the above helps, as you may guess I have been doing the above &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2018 19:06:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7210#M297</guid>
      <dc:creator>skyflier21</dc:creator>
      <dc:date>2018-02-09T19:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Article 5(2) - Demonstrate compliance ... but how?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7303#M301</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GDPR can be a daunting beast. When you come to question like that try and switch places with the Authority.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you visited another organisation and asked them to prove they were carrying out the activities in Paragraph 1, what evidence would you believe?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As mentioned, documentation is a number one item, but you also then need to show that this is being followed and is embedded in culture, not just IT systems (staff awareness and training) e.g., how do you check that privacy has been considered during design, an not just bolted on afterwards; do you have&amp;nbsp; gateway check during project delivery?&lt;/P&gt;&lt;P&gt;On the wider picture, there are organisation that can assist with refining standards into defined control sets, but make sure you do not turn GDPR into a tick and flick exercise - that will undoubtedly result in a fail&amp;nbsp;&lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://community.isc2.org/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2018 08:32:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7303#M301</guid>
      <dc:creator>Elux-Lucis</dc:creator>
      <dc:date>2018-02-12T08:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Article 5(2) - Demonstrate compliance ... but how?</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7425#M306</link>
      <description>&lt;P&gt;Basically evidence and documentation of what you are doing and what you are not doing and why&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 11:10:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Article-5-2-Demonstrate-compliance-but-how/m-p/7425#M306</guid>
      <dc:creator>phollan1</dc:creator>
      <dc:date>2018-02-16T11:10:40Z</dc:date>
    </item>
  </channel>
</rss>

