<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GDPR - Does anyone know of plans to create a certification in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8205#M378</link>
    <description>&lt;P&gt;Hi, &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/554737733"&gt;@Gchanner65&lt;/a&gt;&amp;nbsp; ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, you meant &lt;STRONG&gt;certification:&lt;/STRONG&gt; &lt;EM&gt;a system to validate the compliance of an organisation with the GDPR&lt;/EM&gt;, where I understood you meant &lt;STRONG&gt;certification&lt;/STRONG&gt;: &lt;EM&gt;a system to validate the knowledge of a person about the GDPR&lt;/EM&gt; &lt;img id="manlol" class="emoticon emoticon-manlol" src="https://community.isc2.org/i/smilies/16x16_man-lol.png" alt="Man LOL" title="Man LOL" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Come to think of it, it strikes me as a bit odd that we should have a &lt;EM&gt;certification&lt;/EM&gt; that assures an organisation's compliance &lt;U&gt;with the Law&lt;/U&gt;. They hardly have a choice, do they? To put it bluntly: you can't have any "uncertified" company in the EU, they ALL will &lt;STRONG&gt;have to&lt;/STRONG&gt; comply with the Law, or else!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can, of course, educate people (whom may work in organisations) and test if they understand what it means to comply with the GDPR. And of course, there are certain roles and techniques that not everybody needs to understand,&amp;nbsp; e.g. what a DPO does or how to do a DPIA. So, it makes sense to certify that people that fulfil these roles or use these techniques can be trusted to do so / use them.&amp;nbsp; That's what the IAPP tries to achieve, methinks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - why do we need a certification system for compliance with the GDPR?&lt;/P&gt;</description>
    <pubDate>Wed, 07 Mar 2018 22:49:23 GMT</pubDate>
    <dc:creator>fortean</dc:creator>
    <dc:date>2018-03-07T22:49:23Z</dc:date>
    <item>
      <title>GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8181#M371</link>
      <description>&lt;P&gt;There has been talk about certification but does anyone know if there are serious plans to go down this route&amp;nbsp;&lt;BR /&gt;I am aware that BS 10012:2017 Personal Information Management System is possibly the best option in the short term - interested in your thoughts&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 11:16:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8181#M371</guid>
      <dc:creator>Gchanner65</dc:creator>
      <dc:date>2018-03-07T11:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8183#M373</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EU GDPR Practitioner (EU GDPR P) qualification (ISO 17024-certificated).&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.itgovernance.co.uk/shop/product/certified-eu-general-data-protection-regulation-practitioner-gdpr-training-course" target="_self"&gt;Certified EU General Data Protection Regulation Practitioner (GDPR) Training Course&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attendees take the EU GDPR P exam at the end of the course – a 90-minute, multiple-choice, ISO 17024-certificated exam set by &lt;A href="http://www.ibitgq.org/about-us/ibitgq-advantages.aspx" target="_blank"&gt;&lt;FONT color="#0066cc"&gt;IBITGQ&lt;/FONT&gt;&lt;/A&gt;. There is no extra charge for this exam.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KRS.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 12:03:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8183#M373</guid>
      <dc:creator>KRS</dc:creator>
      <dc:date>2018-03-07T12:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8184#M374</link>
      <description>&lt;P&gt;Hi KRS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am already a EU GDPR-P , I was thinking more on the lines of organizational certification&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 12:24:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8184#M374</guid>
      <dc:creator>Gchanner65</dc:creator>
      <dc:date>2018-03-07T12:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8185#M375</link>
      <description>&lt;P&gt;The gold standard seems to be the &lt;A href="https://iapp.org" target="_self"&gt;IAPP&lt;/A&gt; CIPP/E, CIPT or CIPM accreditation. I'm currently working on obtaining IAPP's CIPP/E certification. There is a good &lt;A href="https://www.rug.nl/rechten/news/archief/2017/university-of-groningen-offers-online-course-about-the-eu-general-data-protection-regulation?lang=en" target="_self"&gt;free on-line course&lt;/A&gt; available to get you started on the GDPR, and I've bought the book "European Data Protection, Law and Practice" edited by Eduardo Ustaran, CIPP/E (available from the IAPP website).&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 13:41:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8185#M375</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-07T13:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8197#M376</link>
      <description>&lt;P&gt;For the &amp;nbsp;"can I get ISO27001 for GDPR compliance" certification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are concepts such as a European Data Protection&amp;nbsp;Seal, but I doubt these will amount to much more than consumer badges of trust. You can have a google, Europrise is the most well-known one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 18:04:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8197#M376</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-03-07T18:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8205#M378</link>
      <description>&lt;P&gt;Hi, &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/554737733"&gt;@Gchanner65&lt;/a&gt;&amp;nbsp; ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, you meant &lt;STRONG&gt;certification:&lt;/STRONG&gt; &lt;EM&gt;a system to validate the compliance of an organisation with the GDPR&lt;/EM&gt;, where I understood you meant &lt;STRONG&gt;certification&lt;/STRONG&gt;: &lt;EM&gt;a system to validate the knowledge of a person about the GDPR&lt;/EM&gt; &lt;img id="manlol" class="emoticon emoticon-manlol" src="https://community.isc2.org/i/smilies/16x16_man-lol.png" alt="Man LOL" title="Man LOL" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Come to think of it, it strikes me as a bit odd that we should have a &lt;EM&gt;certification&lt;/EM&gt; that assures an organisation's compliance &lt;U&gt;with the Law&lt;/U&gt;. They hardly have a choice, do they? To put it bluntly: you can't have any "uncertified" company in the EU, they ALL will &lt;STRONG&gt;have to&lt;/STRONG&gt; comply with the Law, or else!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can, of course, educate people (whom may work in organisations) and test if they understand what it means to comply with the GDPR. And of course, there are certain roles and techniques that not everybody needs to understand,&amp;nbsp; e.g. what a DPO does or how to do a DPIA. So, it makes sense to certify that people that fulfil these roles or use these techniques can be trusted to do so / use them.&amp;nbsp; That's what the IAPP tries to achieve, methinks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - why do we need a certification system for compliance with the GDPR?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 22:49:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8205#M378</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-07T22:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8208#M379</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I barely can see such certification. GDPR is very high level. After you study the regulation you will be able to answer to legal questions only. However, it requires implementation and that does not exist in GDPR text. Moreover, there is a lot of confusion around its implementation. The leading misconception on the market is that vendors proposing to implement "security". However, the core of GDPR is "privacy". While security controls should exist in GDPR implementation (see NIST SP800-53 or ISO 27000 or DSS) real implementation requires PRIVACY controls. That is the problem. Security vendors are not ready to do that. They can recommend say a firewall or logs' analysis but what is "Accounting of Disclosure" they have no clue about. That is one of privacy controls you can find in NIST SP800-53, see Revision 4 or Revision 5 Draft. You can also go on our site &lt;A href="http://www.rubos.com" target="_blank"&gt;www.rubos.com&lt;/A&gt; to see our DeepSec 2012 presentation (in Research) or the presentation text draft (more informative). That was our response to the challenge "How to implement GDPR". We developed the framework for that. You may be interested to see how high level GDPR is converted in software application development logic.&amp;nbsp; Keep in mind - we did that for GDPR draft. Current regulation may have some differences.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 00:58:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8208#M379</guid>
      <dc:creator>mutin</dc:creator>
      <dc:date>2018-03-08T00:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8214#M380</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/113395875"&gt;@mutin&lt;/a&gt;- interesting. I somewhat disagree with the notion that there are no implementation details (at all) in the GDPR, at least the concepts of a DPO and DPIA are given, for example. And, for example, Article 30 clearly indicates - in great detail - which data is to be kept by who (the controller). So, at least the 'what' is specified, and sometimes the 'how' is also quite clear.&amp;nbsp; The GDPR refers to well known concepts in the information security world, e.g. Article 35 (d) refers to doing risk analysis, which has been one of the cornerstones of the infosec field for decades and for which we have a kazillion methodologies ( selecting one involves taking a risk in itself, methinks&amp;nbsp;&lt;img id="manvery-happy" class="emoticon emoticon-manvery-happy" src="https://community.isc2.org/i/smilies/16x16_man-very-happy.png" alt="Man Very Happy" title="Man Very Happy" /&gt; )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I will check out the framework, thanks for the pointer!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 07:50:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8214#M380</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-08T07:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8215#M381</link>
      <description>&lt;P&gt;BTW, sorry to have to say this &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/113395875"&gt;@mutin&lt;/a&gt;, but I find your site a great example of unneccesary obfuscation of possibly usable information. You and I seem to share a character treat: we tend to use too many words to get our point across &lt;img id="smileyembarrassed" class="emoticon emoticon-smileyembarrassed" src="https://community.isc2.org/i/smilies/16x16_smiley-embarrassed.png" alt="Smiley Embarassed" title="Smiley Embarassed" /&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The slides in &lt;A href="http://www.rubos.com/WebSitePapers/DeepSec2012_Presentation.pdf" target="_self"&gt;your presentation&lt;/A&gt; contain a lot of data - actually, they read as if you dumped a paper into powerpoint - and I find it hard to find the core, usable, applicable information. It seems you (or your group) did some good work, for example the comparison between various regulations / laws. The conclusion seems to underline my perception that much that is needed is already available (a core theme in all my work): [...] &lt;EM&gt;our analysis has shown that there is a very strong correlation between privacy controls. In fact, NIST standards supersede old HIPAA, and represent more concrete outcome of EU GDPR.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But maybe the presentation is not the best source for your work - is there a paper we can download and discuss?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ETA-1: &lt;A href="http://www.rubos.com/WebSitePapers/DeepSec2012PresentationTextFinal022013.pdf" target="_self"&gt;just found it!&lt;/A&gt;&lt;/P&gt;&lt;P&gt;ETA-2: but it's still a draft, is there a finished version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 08:22:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8215#M381</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-08T08:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8216#M382</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1277552593"&gt;@fortean&lt;/a&gt;&amp;nbsp;100%. Privacy has a very strong correlation with regards to the appropriate controls for nearly all laws globally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is a 'Character Treat' a cornucopia&amp;nbsp;of pre-conjugated irregular verbs for the delectation of those who wish to obviate the need for obfuscation&amp;nbsp;by steganographic praxis misapplication of a heliocentric orbital Kepler interpretation? I think we should be told.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 11:20:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8216#M382</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-03-08T11:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8217#M383</link>
      <description>&lt;P&gt;Nope, it was a simple typo &lt;img id="manlol" class="emoticon emoticon-manlol" src="https://community.isc2.org/i/smilies/16x16_man-lol.png" alt="Man LOL" title="Man LOL" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ETA: though I must admit that it nicely correlates with "something being a treat" - because a charactertread can be, and often is, a treat!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 12:08:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8217#M383</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-08T12:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8232#M384</link>
      <description>&lt;P&gt;In this age of Intelligence, digital transformation and the driving demand for "trust" and verification.&amp;nbsp;&amp;nbsp; It might be seen to be inevitable, especially if cyber insurance organisations are becoming more involved and expect "warranties" from vendors.&amp;nbsp; The demand may arise for countries, outside of the EU i.e. Cloud Providers as verification they comply with the TOMs and via contracts etc.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute-Cautim&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 19:39:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8232#M384</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-03-08T19:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8234#M385</link>
      <description>&lt;P&gt;Excellent point! Indeed, it may be useful for non-EU based organisations willing to adhere to this new standard.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 19:49:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8234#M385</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-08T19:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8236#M386</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1277552593"&gt;@fortean&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Excellent point! Indeed, it may be useful for non-EU based organisations willing to adhere to this new standard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason it may be inevitable is like the case of Lloyds Bank in UK, some time back they outsourced entirely to India their back ends.&amp;nbsp; More and more organisations will go for the cheapest resources, including cloud providers etc.&amp;nbsp; Plus the other driver is AI, predictive analytics, Big Data and the requirement to share statistics and other related information in this digital economy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We simply have to trust each other, in order make this information age or phase 5 - Intelligence actually work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, on the other side, we have the other economy, within the Dark Web, willing to exploit it and sell data records to the highest bidder etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 19:56:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8236#M386</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-03-08T19:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8242#M388</link>
      <description>&lt;P&gt;Barclays is (still) an EU based organisation and hence is bound to adhere to the Law (GDPR).&amp;nbsp; But even if they were not, they will most probably have to handle PI from EU 'data subjects' which reside on EU territory and as Barclays offers services - the GDPR applies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A big question is, of course, how the EU can enforce their Laws outside the EU. However, given the economical importance of the EU, most companies will gladly adhere to the EU rules, especially if - as is the case in the UK - the culture and habits are quite similar to those of many countries in the EU.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently doing a course on the GDPR (preparing for CIPP/E, actually) and one of the students (Richard Cooke) pointed me towards &lt;A href="https://www.linkedin.com/pulse/territorial-scope-gdpr-flowchart-siarhei-varankevich" target="_self"&gt;this IMHO very helpful figure&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a.png" style="width: 569px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2154iC7B1D85CC09FA2CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="a.png" alt="a.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 20:17:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8242#M388</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-08T20:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8288#M390</link>
      <description>&lt;P&gt;A quote from the course I'm currently taking:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Certification mechanisms&lt;P&gt;&lt;STRONG&gt;Data protection certification mechanisms&lt;/STRONG&gt;, &lt;STRONG&gt;seals&lt;/STRONG&gt; and &lt;STRONG&gt;marks&lt;/STRONG&gt; (&lt;A href="http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&amp;amp;from=EN#page=58" target="_blank"&gt;Article 42&lt;/A&gt;) can also be used as evidence to demonstrate compliance with the GDPR. Certification is voluntary and available via a transparent process. Criteria for certification are approved by competent supervisory authorities and certification is issued by accredited certification bodies or competent supervisory authorities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The general idea seems to be that these mechanisms will be used to ascertain compliancy of data processors and data controllers with the GDPR. As I stated before all and every EU based organisation SHOULD be GDPR-compliant - the GDPR is Law, after all. But many smaller and very small companies may have doubts if they really comply with the GDPR (bigger companies have law departments, controllers, internal auditors and such to guide them) and may find it re-assuring to know they are compliant within the bounds of reasonable doubt. In such situations certification bodies may issue seals of approval (certifications) that may help them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, as said before: it also helps to certify bodies that formally do not have to comply with the GDPR but simply want to and want some independent proof they do.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 14:00:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8288#M390</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2018-03-09T14:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8414#M396</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for all your replies. If you are interested in continuing the discussion (I'm always pro) then it would be better over regular email. I'm not sure if people are interested in details of our conversation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, our presentations reflect our style - minimal pictures and maximum information. The reason is very practical - in a case we do not publish article and/or it will be several months later we provide people as much as possible information to consider. In publications of our presentations we work closely with DeepSec and giving guys the chance to publish what they first provided the ground to present. So far they published two (actually three) or our presentations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, you found the draft - no, unfortunately we did not published "clean" article. And frankly, we still do not have time for. Unless DeepSec will agree to return to our presentation in question as EU faces big yet to fail event - Compliance Day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Concerning controls and implementation. Security controls - they should be like DSS or NIST, but NOT HIPAA style. People should not scratch heads what exactly to do. It should be up to the level like "Two-Factor Authentication" and thus if a person understands the meaning then there are no other questions.&lt;/P&gt;&lt;P&gt;That is not going to happen to NIST Privacy Controls nor to GDPR. The implementation is very complex and in our Draft we provided an example as "framework". We may do mistakes and being somewhere incorrect in complex logic, but the most important is to show if it is possible to do and what it generally means.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have more questions or comments let's do over mutin@rubos.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again for your input!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mikhail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: we are now deeeeep in Malicious Hypervisor APT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 01:43:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8414#M396</guid>
      <dc:creator>mutin</dc:creator>
      <dc:date>2018-03-13T01:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8501#M401</link>
      <description>&lt;P&gt;&lt;SPAN&gt;On ‎11-28-2017, I published in this GDPR Discussion the following news:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"ENISA report: Concepts and recommendations on European Data Protection Certification mechanisms"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;you may perhaps read &lt;A href="https://www.enisa.europa.eu/publications/recommendations-on-european-data-protection-certification" target="_self"&gt;this report&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 09:42:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8501#M401</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2018-03-17T09:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR - Does anyone know of plans to create a certification</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8517#M404</link>
      <description>&lt;P&gt;Thank you nice one!!&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/337643415"&gt;@leroux&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;&lt;SPAN&gt;On ‎11-28-2017, I published in this GDPR Discussion the following news:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"ENISA report: Concepts and recommendations on European Data Protection Certification mechanisms"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;you may perhaps read &lt;A href="https://www.enisa.europa.eu/publications/recommendations-on-european-data-protection-certification" target="_self"&gt;this report&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Mar 2018 20:44:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Does-anyone-know-of-plans-to-create-a-certification/m-p/8517#M404</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2018-03-18T20:44:25Z</dc:date>
    </item>
  </channel>
</rss>

