In preparation for the May 25th deadline, a compliance roadmap was created. Data protection policies and procedures have been updated and technical safeguards implemented. SANS today, is fully compliant with privacy laws, and will remain so going forward. The SANS Institute is ready for GDPR.
The SANS Institute welcomes the GDPR and recognizes it as a significant step forward for data privacy and rights of individuals. It provides a great opportunity to tighten security controls and process, as well as provide transparency into what personal data SANS collects and how it is securely processed and stored. This helps empower our customers to manage the use of their data. SANS has carefully reviewed the requirements and recitals of GDPR and are carefully making enhancements to our products, systems, contracts, and services to ensure compliance and the safeguarding of our customers data.
"The EU General Data Protection Regulation (GDPR) replaces the Data Protection Directive 95/46/EC and was designed to harmonize data privacy laws across Europe, to protect and empower all EU citizens data privacy and to reshape the way organizations across the region approach data privacy... " - eugdpr.org
Major Provisions
Simply put, the GDPR mandates a baseline set of standards for companies that handle EU citizens' data to better safeguard the processing and movement of citizens' personal data.
GDPR covers personal data
GDPR further defines this as follows:
Personal data means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
"Any information" - cookies, images, names, email addresses, employee numbers, location, occupation, gender, account records, etc. This is generally considered to be literal... any information relating to a data subject.
Proper collection for purpose, processing of personal data. GDPR states that data collected must be relevant for our intended purpose and that it needs to be collected for specified, explicit, and legitimate purposes.
Conditions for consent require notification to data subjects using concise, transparent, intelligible and easily accessible language. GDPR also gives EU citizens the right to withdraw their consent at any time.
GDPR also gives data subjects more control over personal data that is processed automatically. The result is that data subjects may transfer their personal data between service providers more easily (also called the "right to portability"), and they may direct a controller to erase their personal data under certain circumstances (also called the "right to erasure").
Notification to EU citizens upon data collection or acquisition. Notification must be provided with a reasonable period after obtaining the data not exceeding on month. The notification must include:
GDPR describes the requirements for the communication of a data breach involving EU citizen personal data.
GDPR addresses the need for the controller to , while taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.
It also addresses secure storage of data, ongoing security, integrity and availability of data and the ability to restore availability within a timely manner. It also calls for regular testing and evaluation of effectiveness of technical and organizational measures ensuring the security of the data.
And, it requires that companies to perform Data Protection Impact Assessments to identify risks to consumer data and Data Protection Compliance Reviews to ensure those risks are addressed.
The GDPR requires that certain companies appoint data protection officers; these officers serve to advise companies about compliance with the regulation and act as a point of contact with Supervising Authorities (SAs).
It outlines the data protection officer position and its responsibilities in ensuring GDPR compliance as well as reporting to Supervisory Authorities and data subjects.
The DPO shall:
GDPR extends requirements to international companies that collect or process EU citizens' personal data, subjecting them to the same requirements and penalties as EU-based companies.
It also outlines the penalties for GDPR non-compliance, which can be up to 4% of the violating company's global annual revenue depending on the nature of the violation.
EU GDPR categorizes data holders into two groups: processors and controllers.
In short, Privacy Shield allows US companies, or EU companies working with US companies, to meet the international data transfer requirements of the GDPR.