Book description
An in-depth guide to the changes your organization needs to make to comply with the EU GDPR.
The EU General Data Protection Regulation (GDPR) will supersede the 1995 EU Data Protection Directive (DPD) and all EU member states’ national laws based on it – including the UK Data Protection Act 1998 – in May 2018.
All organizations – wherever they are in the world – that process the personally identifiable information (PII) of EU residents must comply with the Regulation. Failure to do so could result in fines of up to €20 million or 4% of annual global turnover.
US organizations that process EU residents’ personal data can comply with the GDPR via the EU-US Privacy Shield, which replaced the EU-US Safe Harbor framework in 2016. The Privacy Shield is based on the DPD, and will likely be updated once the GDPR is applied in May 2018.
This book provides a detailed commentary on the GDPR, explains the changes you need to make to your data protection and information security regimes, and tells you exactly what you need to do to avoid severe financial penalties.
Product overview
EU GDPR – An Implementation and Compliance Guide is a clear and comprehensive guide to this new data protection law, explaining the Regulation, and setting out the obligations of data processors and controllers in terms you can understand.
Topics covered include:
The role of the data protection officer (DPO) – including whether you need one and what they should do.
Risk management and data protection impact assessments (DPIAs), including how, when and why to conduct a DPIA.
Data subjects’ rights, including consent and the withdrawal of consent; subject access requests and how to handle them; and data controllers’ and processors’ obligations.
International data transfers to “third countries” – including guidance on adequacy decisions and appropriate safeguards; the EU-US Privacy Shield; international organizations; limited transfers; and Cloud providers.
How to adjust your data protection processes to transition to GDPR compliance, and the best way of demonstrating that compliance.
A full index of the Regulation to help you find the articles and stipulations relevant to your organization.
The GDPR will have a significant impact on organizational data protection regimes around the world. EU GDPR – An implementation and Compliance Guide shows you exactly what you need to do to comply with the new law.
About the authors
IT Governance is a leading global provider of IT governance, risk management, and compliance expertise, and we pride ourselves on our ability to deliver a broad range of integrated, high-quality solutions that meet the real-world needs of our international client base.
Our privacy team – led by Alan Calder, Richard Campo, and Adrian Ross – has substantial experience in privacy, data protection, compliance, and information security. This experience, and our understanding of the background and drivers for the GDPR, are combined in this manual to provide the world’s first guide to implementing the new data protection regulation.
Table of contents
- Cover
- Title
- Copyright
- About the Author
- Contents
- Introduction
- Chapter 1: Privacy Compliance Frameworks
-
Chapter 2: Role of the Data Protection Officer
- Voluntary designation of a Data Protection Officer
- Undertakings that share a DPO
- DPO on a service contract
- Publication of DPO contact details
- Position of the DPO
- Necessary resources
- Acting in an independent manner
- Protected role of the DPO
- Conflicts of interest
- Specification of the DPO
- Duties of the DPO
- The DPO and the organisation
- The DPO and the supervisory authority
- Data protection impact assessments and risk management
- In house or contract
-
Chapter 3: Common Data Security Failures
- Personal data breaches
- Anatomy of a data breach
- Sites of attack
- Securing your information
- ISO 27001
- Ten Steps to Cyber Security
- Cyber Essentials
- NIST standards
- The information security policy
- Assuring information security
- Governance of information security
- Information security beyond the organisation’s borders
- Chapter 4: Six Data Protection Principles
- Chapter 5: Requirements for Data Protection Impact Assessments
- Chapter 6: Risk Management and DPIAs
- Chapter 7: Data Mapping
- Chapter 8: Conducting DPIAs
- Chapter 9: Data Subjects’ Rights
- Chapter 10: Consent
- Chapter 11: Subject Access Requests
- Chapter 12: Controllers and Processors
- Chapter 13: Managing Personal Data Internationally
- Chapter 14: Incident Response Management and Reporting
- Chapter 15: GDPR Enforcement
- Chapter 16: Transitioning and Demonstrating Compliance
- Appendix 1: Index of the Regulation
- Appendix 2: EU/EEA National Supervisory Authorities
- Appendix 3: Implementation FAQs
- ITG Resources
Product information
- Title: EU General Data Protection Regulation (GDPR): An Implementation and Compliance Guide
- Author(s):
- Release date: November 2016
- Publisher(s): IT Governance Publishing
- ISBN: 9781849288378
You might also like
book
EU General Data Protection Regulation (GDPR): An Implementation and Compliance Guide - Second edition
The updated second edition of the bestselling guide to the changes your organisation needs to make …
book
EU General Data Protection Regulation (GDPR) – An implementation and compliance guide, fourth edition
This bestselling guide is the ideal companion for anyone carrying out a GDPR (General Data Protection …
book
EU General Data Protection Regulation (GDPR), third edition - An Implementation and Compliance Guide
EU GDPR – An Implementation and Compliance Guide is a perfect companion for anyone managing a …
video
General Data Protection Regulation Foundation (GDPR F)
GDPR Foundation training enables you to learn the basic elements to implement and manage a compliance …