<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GDPR for offshore company in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8899#M426</link>
    <description>&lt;DIV class="lia-message-author-with-avatar"&gt;Very good answer. But do you have some checklist with all GDPR requiriments?&lt;/DIV&gt;</description>
    <pubDate>Wed, 28 Mar 2018 20:26:46 GMT</pubDate>
    <dc:creator>felipetsi</dc:creator>
    <dc:date>2018-03-28T20:26:46Z</dc:date>
    <item>
      <title>GDPR for offshore company</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8886#M424</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm in the process of implementing ISO 27001 for an accounting firm in&amp;nbsp;India who processes data of customers in UK. I believe the firm also needs to be complied to GDPR, what would be compliance requirements should I consider?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 17:18:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8886#M424</guid>
      <dc:creator>Buddhika_dalwis</dc:creator>
      <dc:date>2018-03-28T17:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR for offshore company</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8893#M425</link>
      <description>&lt;P&gt;When implementing ISO27001 you must examine content 1. Regulations, 2. Contracts and 3 Security Policy , so your security policy will have to ensure that GDPR compliance is part of the regulation, and your context.&amp;nbsp;With GDPR DPIA ( Data Protection Impact Assessment) is the key part of it, and you have to use this as &amp;nbsp;part of your risk assessment analyses, risk register and SOA for ISO27001 controls.&lt;/P&gt;&lt;P&gt;Go through your Annex A controls, and utilising your DPIA define your Statement of Applicability and incorporate that into your ISO27001 documentation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 19:52:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8893#M425</guid>
      <dc:creator>sanya_s</dc:creator>
      <dc:date>2018-03-28T19:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR for offshore company</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8899#M426</link>
      <description>&lt;DIV class="lia-message-author-with-avatar"&gt;Very good answer. But do you have some checklist with all GDPR requiriments?&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Mar 2018 20:26:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8899#M426</guid>
      <dc:creator>felipetsi</dc:creator>
      <dc:date>2018-03-28T20:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR for offshore company</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8910#M427</link>
      <description>&lt;P&gt;Suggest you use the PIA guidance provided bu CNIL (available in english!) whuich you will find at&amp;nbsp;&lt;A href="https://www.cnil.fr/en/home" target="_blank"&gt;https://www.cnil.fr/en/home&lt;/A&gt;. That will take you through and guide your approach.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 23:13:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-for-offshore-company/m-p/8910#M427</guid>
      <dc:creator>ajyoung</dc:creator>
      <dc:date>2018-03-28T23:13:27Z</dc:date>
    </item>
  </channel>
</rss>

