<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR) in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/525#M8</link>
    <description>&lt;P&gt;Great summary. Thank you. GDPR is specifically calling out the monitoring/tracking and profiling aspect. I am sure this will impact most organizations using Google Analytics and other tools to gather more stats on page views, time spent in each page ..etc. The cookies used in this case may not "identify" data subjects by theirs ids but do identify the data subjects by their organization, geo location ..etc. Any idea on whether a specific consent has to be obtained for this monitoring? For example, as a Data Processor, the data subject may consent to the use of cookies at the processor's site. But then how about the use of the third party cookies? Any idea whether a special consent has to be obtained for each such third party or the Data Processor can combine them into their own cookie policy by identifying the third parties explicitly or implicitly? Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Sun, 08 Oct 2017 17:20:26 GMT</pubDate>
    <dc:creator>2012</dc:creator>
    <dc:date>2017-10-08T17:20:26Z</dc:date>
    <item>
      <title>Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/169#M6</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="container"&gt;&lt;DIV class="pkg"&gt;&lt;DIV class="row"&gt;&lt;DIV&gt;&lt;DIV class="pkg"&gt;&lt;DIV&gt;&lt;DIV class="pkg"&gt;&lt;DIV class="entry-category-confidentiality entry-category-current_affairs entry-category-government_ entry-category-legal entry-category-privacy entry-category-risk entry-author-isc_management entry-type-post entry"&gt;&lt;DIV class="entry-inner"&gt;&lt;DIV class="entry-content"&gt;&lt;DIV class="entry-body"&gt;&lt;P&gt;The (ISC)²&amp;nbsp;EMEA Advisory Council GDPR Task Force has published an &lt;SPAN class="asset  asset-generic at-xid-6a00e54f109b67883401b8d258d5c6970c img-responsive"&gt;&lt;A href="http://blog.isc2.org/files/getting-started-on-the-basics-the-eu-general-data-protection-regulation-gdpr.pdf" target="_blank"&gt;overview of the basics&lt;/A&gt;&lt;/SPAN&gt; that can be used as a tool to help everyone understand and communicate the scope of what is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;This document was prepared by members of the (ISC)2 EMEA Advisory Council GDPR Task Force. Lead Contributors: Yves Le Roux, CISSP, CISM; Paul Lanois, CCSK, CIPM, CIPT, CIPP (A, E, US and C), FIP, CISMP and LLM.&lt;BR /&gt;Reviewed by Dr. Adrian Davis, MBA, FBCS CITP, CISSP; Sam Berger, CISSP; Michael Christensen, CISSP, CSSLP, CISM, CRISC, CIS LI, EU-GDPR-P; CCM, CCSK, CPSA, ISTQB, PRINCE2, ITIL, COBIT5; Ramon Codina, CISSP; Santosh Krishna Putchala, CISSP&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:17:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/169#M6</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2023-10-09T08:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/218#M7</link>
      <description>&lt;P&gt;This is great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I ask if you know how I could get involved and be on the, "&lt;SPAN&gt;(ISC)&lt;/SPAN&gt;&lt;SPAN&gt;2 &lt;/SPAN&gt;&lt;SPAN&gt;EMEA Advisory Council GDPR Task Force"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am based in Hong Kong and GDPR is one of the key focus areas of my current work (as well as China Cyber Security Law) and it is impacting many international organizations around the world. &amp;nbsp;I have also presented this topic and cyber security at ISACA's Chapter, and hosted several GDPR events with the company I work for.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would love to hear from you, to see how I could contribute / assist from an "Asia Pacific" perspective.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jason Lau&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;CISSP, CGEIT, CRISC, CISM, CISA, CEH, CNDA, CSM, ITIL&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.linkedin.com/in/jasonwklau/" target="_blank"&gt;https://www.linkedin.com/in/jasonwklau/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2017 13:26:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/218#M7</guid>
      <dc:creator>jasonlau88</dc:creator>
      <dc:date>2017-10-08T13:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/525#M8</link>
      <description>&lt;P&gt;Great summary. Thank you. GDPR is specifically calling out the monitoring/tracking and profiling aspect. I am sure this will impact most organizations using Google Analytics and other tools to gather more stats on page views, time spent in each page ..etc. The cookies used in this case may not "identify" data subjects by theirs ids but do identify the data subjects by their organization, geo location ..etc. Any idea on whether a specific consent has to be obtained for this monitoring? For example, as a Data Processor, the data subject may consent to the use of cookies at the processor's site. But then how about the use of the third party cookies? Any idea whether a special consent has to be obtained for each such third party or the Data Processor can combine them into their own cookie policy by identifying the third parties explicitly or implicitly? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2017 17:20:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/525#M8</guid>
      <dc:creator>2012</dc:creator>
      <dc:date>2017-10-08T17:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/588#M9</link>
      <description>&lt;P&gt;This is a really good, punchy paper that lays out the implications of the GDPR very nicely. It's also helpful that it comes with the (ISC)2 imprimatur rather than that of an organisation that has a related product or service to sell. Thank you - I shall be putting it to use.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2017 19:07:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/588#M9</guid>
      <dc:creator>TimG</dc:creator>
      <dc:date>2017-10-08T19:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/605#M10</link>
      <description>Has anyone experience of applying privacy threat models, I have seen LINDDUN referenced but haven't seen an application of it.&lt;BR /&gt;&lt;A href="https://linddun.org/" target="_blank"&gt;https://linddun.org/&lt;/A&gt;</description>
      <pubDate>Sun, 08 Oct 2017 19:50:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/605#M10</guid>
      <dc:creator>Robert</dc:creator>
      <dc:date>2017-10-08T19:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/757#M11</link>
      <description>&lt;P&gt;Consent is required for the likes of Google Analytics but this is under the e-Privacy directive. With cookies I think this directive takes precedence over the Electronic Communications Directive. The e-Privacy directive will be a regulation roughly at the same time as the GDPR if the EU has its way...&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 08:28:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/757#M11</guid>
      <dc:creator>SteveE</dc:creator>
      <dc:date>2017-10-09T08:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/912#M12</link>
      <description>&lt;P&gt;I also echo&amp;nbsp;&lt;SPAN class=""&gt;jasonlau88's request to see if I could be added to the "&lt;SPAN&gt;(ISC)2 EMEA Advisory Council GDPR Task Force" or participate in discussions.&amp;nbsp; I work for a global cloud-based company that is working to comply with the GDPR as well and would love to work with the group to determine how to approach this regulation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 16:29:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/912#M12</guid>
      <dc:creator>briandrutledge</dc:creator>
      <dc:date>2017-10-09T16:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/957#M13</link>
      <description>&lt;P&gt;As a service to the Dutch and Flemish communities I prepared a Dutch translation, which I gladly will post wherever the authors feel it is appropriate. Authors, please contact me for further details so we can make arrangements.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:10:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/957#M13</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2017-10-09T19:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1004#M14</link>
      <description>&lt;P&gt;If you quoted the origin, the GDPR Task Force has decided to authorize any use of this paper for (ISC)² chapters. Consequently, any translation will be apprciated...&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2017 06:53:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1004#M14</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2017-10-10T06:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1005#M15</link>
      <description>&lt;P&gt;It may be interesting to have an open discussion upon GDPR Implementations in this community....&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2017 06:54:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1005#M15</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2017-10-10T06:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1056#M16</link>
      <description>&lt;P&gt;Ah, yes, of course I mentioned the origin.&amp;nbsp; Oddly enough we don't seem to have an upload facility here, or I would have uploaded the document here for further review. I will see if we can get the document posted on our chapter's website, and we may mail it to our chapter members. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2017 15:09:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1056#M16</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2017-10-10T15:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1227#M17</link>
      <description>&lt;P&gt;Agreed, an open discussion here on GDPR implementation would be great.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 15:25:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1227#M17</guid>
      <dc:creator>planois</dc:creator>
      <dc:date>2017-10-12T15:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1228#M18</link>
      <description>&lt;P&gt;Any "open" discussion tends to get unfocused and hence of limited value. So, perhaps we should intentionally limit the discussion somewhat to certain aspects of the GDPR, or implementation for certain types of organisations?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 15:31:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1228#M18</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2017-10-12T15:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1268#M19</link>
      <description>&lt;P&gt;Dear Heinrich,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That would be welcome and are very glad for your support!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lea&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 09:39:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1268#M19</guid>
      <dc:creator>Lea_Friend</dc:creator>
      <dc:date>2017-10-13T09:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1269#M20</link>
      <description>&lt;P&gt;Okay, so to kick things off: the GDPR is probably a "hot" topic for most bigger companies / organisations. They will mostly have resources to implement the GDPR. But how about the smaller organisations? How can we, the (ISC)2 community, help them to adhere to the new rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some challenges I can imagine that those small(er) companies have w/regard to the GDPR:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;limited knowledge and not much funds to hire specialists&lt;/LI&gt;&lt;LI&gt;they are probably hampered in finding specialists anyway. Firstly, we have a huge shortage on the market. So, if smaller companies actually consider hiring a specialist - well, most of them will be employed by the larger companies. Let's be brutally honest here: if I had to choose between being the (ad interim?) DPO / (C)SO for a top-500 company that pays, let's say, 200 credits per hour, or the DPO for a smaller company that just can afford to pay me 100 credits per hour, I would probably pick the top-500 company, as it pays better, comes with more responsibilities and offers a better perspective for interesting work.&lt;/LI&gt;&lt;LI&gt;limited knowledge also may imply they can not really judge the quality of the specialists they hire - and properly certified specialists may be too costly for them, so chances are they'll end up with a lesser god;&lt;/LI&gt;&lt;LI&gt;the illusion that it does not matter to them.&amp;nbsp; "We're a small company. So, okay, we deal with a lot of privacy related information, but we don't make much money, they'll go for the big fish first."&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;some may not even be aware of the GDPR! We, information security specialists may find that hard to believe, but I've seen some examples..&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you think there are more risks to consider, list them here. Also, I'd like to hear your opions and perhaps we might discuss some solutions.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 10:09:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1269#M20</guid>
      <dc:creator>fortean</dc:creator>
      <dc:date>2017-10-13T10:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1389#M29</link>
      <description>&lt;P&gt;I agree with Heinrich and would also add that there is a lit of fearmongering started by "privacy experts" with little or no experience in privacy or information security. I lost count of the number of such "experts" selling their "expertise", yet when you check their background profile, they do not have any experience in privacy or information security: too many of such "experts" were actually, not even 3 months ago, business development managers or salespersons...&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 00:41:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1389#M29</guid>
      <dc:creator>planois</dc:creator>
      <dc:date>2017-10-18T00:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1592#M30</link>
      <description>&lt;P&gt;I have been working at a small NGO managing a website where personal information of individuals giving money online and thirdparty&amp;nbsp;google analytics software is installed. With a team of less than five individuals in the IT/communications department, implementing the GDPR was a constant pain that we still had not figured out on how to become and remain compliant. The discussions here might help.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 09:53:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1592#M30</guid>
      <dc:creator>mganga2k</dc:creator>
      <dc:date>2017-10-26T09:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1601#M31</link>
      <description>&lt;P&gt;&lt;SPAN&gt;A good paper, which takes a complex regulation and presents it simply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to comment on a couple of points:&amp;nbsp; It is stated that:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;“It will become mandatory (Article 33 of the GDPR) for an organisation to report any data breach to its &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;DPA within 72 hours of becoming aware of it”.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It should be noted that the Data Controllers should conduct an assessment of the impact on the data subjects, and if there is no&lt;STRONG&gt; IMPACT&lt;/STRONG&gt;, they do not need to report the data breach. For example, if, say, a laptop is lost that contains personal data, that is a data breach. If however the laptop has appropriate encryption, GDPR deems that there will be no impact to the data subjects, and as such the breach does not need to be reported.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The section on the data register quotes the regulation as saying the register must include:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;“The name and contact details of the controller and, where applicable, the joint controller, the &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;controller's representative and the data protection officer”.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The phrase &lt;STRONG&gt;&lt;EM&gt;“where applicable”&lt;/EM&gt;&lt;/STRONG&gt; should be emphasised, as not all organisations are required to have a Data Protection Officer (DPO). Without getting bogged down in details, there are many liabilities to having a Data Protection Officer, and if an organisation wanted to have one man in charge, then my suggestion would be now, with GDPR, to give him any title you wish, except calling him the Data Protection Officer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This rather brings me to agreeing with &lt;U&gt;&lt;A href="https://community.isc2.org/t5/user/viewprofilepage/user-id/968044487" target="_blank"&gt;planois&lt;/A&gt; &lt;/U&gt;and &lt;/SPAN&gt;Heinrich, that quality of resource is an issue, but in some ways “Privacy Professionals” may not offer the complete skillset necessary to implement GDPR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the reality that in 1984 when the Data Protection Act (DPA) was written into UK law, there was not a lot of computer data about. Organisations by and large regarded the DPA as the digital equivalent to Health&amp;amp;Safety, and I remember, when I first conducted such a project, the absence of executive support. Consequently DPOs were appointed with no real authority to engage their businesses. Even when the EU directive in 95 caused the UK to roll the 84 Act and the 87 Access to Files Act into, what was to become the so-called 98 Act, little really changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my opinion, to implement GDPR compliance, requires a knowledge of GDPR, a knowledge of information security, a knowledge of business continuity, and a knowledge of data architecture, and Privacy Enhanced Technologies (PETS). As this is not likely to be found in one person, the real requirement is excellence in Project and/or Programme management in general, and transformation project management in particular, and only after Executive support is gained.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John McGill&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 10:12:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1601#M31</guid>
      <dc:creator>EUGDPR</dc:creator>
      <dc:date>2017-10-26T10:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1617#M32</link>
      <description>&lt;P&gt;I have read so much about&amp;nbsp;&lt;SPAN&gt;The EU General Data Protection Regulation (GDPR) and the coming into effect in may 2018...its appeared, this is specifically&amp;nbsp;for European ( i stand to be corrected)&amp;nbsp;my question is what role does this play for Africa if at all its might affect it&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 10:35:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1617#M32</guid>
      <dc:creator>Sholaremu</dc:creator>
      <dc:date>2017-10-26T10:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started on the Basics: The EU General Data Protection Regulation (GDPR)</title>
      <link>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1632#M33</link>
      <description>&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;P&gt;Sholaremu,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The General Data Protection Regulation (GDPR) is focused on the rights to privacy of any living person in the European Union.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simplistically, if any organisation, worldwide, wants to do business with the EU, it must comply with GDPR.&lt;/P&gt;&lt;P&gt;Additionally, any organisation which processes personal data pertaining to a living individual in the EU, must comply with GDPR. The term “processes” can just mean that it stores that data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John McGill&lt;/P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Viewer-II lia-component-message-view-widget-author-username"&gt;&lt;A href="https://community.isc2.org/t5/user/viewprofilepage/user-id/848949281" target="_self"&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 26 Oct 2017 11:01:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Getting-Started-on-the-Basics-The-EU-General-Data-Protection/m-p/1632#M33</guid>
      <dc:creator>EUGDPR</dc:creator>
      <dc:date>2017-10-26T11:01:34Z</dc:date>
    </item>
  </channel>
</rss>

