53
GDPR Explained Jan Smets @ GDPR Event 18/05/2017 Pre-Sales Manager DPO Certified

GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Embed Size (px)

Citation preview

Page 1: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

GDPR Explained

Jan Smets @ GDPR Event 18/05/2017

Pre-Sales Manager

DPO Certified

Page 2: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

GDPRis enforced

for EVERY ORGANISATION

(unless household use)

18/05/2017GDPR Explained2

Page 3: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Step by step

GDPR EXPLAINED

18/05/2017GDPR Explained3

Page 4: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained4

Page 5: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

GDPR Legislation

Translate GDPR for your specific situation

Go and read the legislation:

English

Dutch

French

NOTE: skip the first part, and start from Chapter 1, read the rest later

18/05/2017GDPR Explained5

Page 6: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained6

Page 7: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

DPO

Public authority or body (except courts)

Core activities (regular / systematic / large scale)

Monitoring of data subjects

Special categories *

Criminal convictions and offences

Each country can define more rules for appointing DPO

18/05/2017GDPR Explained7

Page 8: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

DPO: Special categories

Racial or ethnic origin

Political opinions

Religious or philosophical beliefs

Trade union membership

Genetic & biometric data for identifying a natural person

Health

Sex life or sexual orientation

18/05/2017GDPR Explained8

Page 9: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained9

Page 10: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Consent & Rights

Easy to give and withdraw consent

Children (-16) need parental consentCan be (-13) in some countries

Rightsto rectification

to erasure

to be forgotten

to restriction of processing

to data portability

18/05/2017GDPR Explained10

Page 11: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained11

Page 12: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Roadbook / Data Register

Never ending story …

Write down all:ResearchFindingsDecisionsActionsRisks…EVERYTHING

Obligation from 250+ employees

Necessary for GDPR compliance!

18/05/2017GDPR Explained12

Page 13: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained13

Page 14: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Data classification

Find PII (Personal Identifiable Information)

Where are they stored?

Who has access?

Who are they shared with?

Which applications process the data?

18/05/2017GDPR Explained14

Page 15: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Priority

18/05/2017GDPR Explained15

Page 16: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Top priorities

Start with data/application:

Most private data

Highest risk of data breach

Use PIA / DPIA

Legacy vs. New application

18/05/2017GDPR Explained16

Page 17: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained17

Page 18: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Procedures & policies

People are and will stay the weakest link

Use procedures / policies

NOT to annoy employees

BUT to keep them on the right track

Privacy by Design: Allow but monitor

18/05/2017GDPR Explained18

Page 19: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained19

Page 20: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Data protection

Production data

Back-ups

Historical data (full detail)Limitations apply

Historical data (analytics)

Encryption

Tokenization

Pseudonymization

Anonymization

18/05/2017GDPR Explained20

Page 21: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained21

Page 22: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Assess & document other risks

Find all other risks

Assess

Document

18/05/2017GDPR Explained22

Page 23: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

18/05/2017GDPR Explained23

Page 24: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Revise and repeat

Revise outcome previous steps

Change where necessary

Find next priority

Repeat steps 4 to 6

18/05/2017GDPR Explained24

Page 25: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Overview

1. Legal framework / Understand GDPR

2. Create roadbook / Data register

3. Data classification

4. Start with top priorities

4a. Procedures & Policies

4b. Data protection

5. Assess & document other risks

6. Revise & repeat

18/05/2017GDPR Explained25

Page 26: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

In short

Legal aspects

Documentation

Privacy By Design

18/05/2017GDPR Explained26

Page 27: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Privacy By Design – 7 principles

Proactive & Preventative

Default setting

Embedded in design

Positive-sum

End-to-end security

Visibility and transparency

User-centric

18/05/2017GDPR Explained27

Page 28: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Gemalto vision

GDPR EXPLAINED

18/05/2017GDPR Explained28

Page 29: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

A new mindset

Accept the Breach

Protect What Matters,

Where It Matters

2

Secure the Breach

3

Perimeter security alone is no

longer enough.

Data is the new perimeter.

Attach security to the data and

applications. Insider threat is

greater than ever.

Gemalto Research: www.breachlevelindex.com

1

18/05/2017GDPR Explained29

Page 30: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Three pilars

18/05/2017GDPR Explained30

Page 31: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Authentication

GDPR EXPLAINED

18/05/2017GDPR Explained31

Page 32: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Why two-factor authentication?

Audit trail for GDPR compliancy

who accessed

at what time

which information

Reduce risk for stolen credentials

Breach prevention

18/05/2017GDPR Explained32

Page 33: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

SafeNet Authentication Service by the Numbers

Over 4.000.000 users of Cloud Edition

30 minutes to set up

400+ fully-tested integrations

60% lower TCO than other solutions

99.999% Availability SLA

18/05/2017GDPR Explained33

Page 34: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

SafeNet Authentication Service

Broad Choice of 2FA Methods and Tokens• OTP, OOB and pattern-based authentication with hardware, software and tokenless form factors• Over-the-air provisioning of tokens ideal for remote staff, partners and contractors

Fully Automated Management• Define policies once, and enforce them throughout your IT ecosystem• Automated user & token lifecycle administration, self-service portals • automated alerts and reporting

Standards-based Security• ISO 27001:2013, AICPA SOC-2 Recognition• FIPS 140-2 validated software tokens, DSKPP-secured provisioning• Hardware-based root of trust (token secrets and encryption keys secured in an HSM)• DSKPP secure provisioning for software tokens

Shared Services with Multi-tier Multi-tenant Architecture • Allows delegation of administration to local or remote staff• Shared services model enables accounting and inventory management per BU• Fully customizable security policies, fully brandable interface

Cloud Efficiencies• Extend current identities to the cloud with native identity federation via SAML 2.0 • Up to 60% savings in deployment and day-to-day administration costs

Broad Use Case Support• VPN, VDI, cloud, network access, portals

18/05/2017GDPR Explained34

Page 35: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

PKI: Protecting Identities and Data

• Large enterprises

• Governments and local

municipalities

• Healthcare organizations

• Critical infrastructure

• Law enforcement

• Financial services

OUR CLIENTS

Management & Software

OUR SOLUTIONS

Middleware

Authenticators & Readers

MobilePKI

18/05/2017GDPR Explained35

Page 36: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Crypto / Data protection

GDPR EXPLAINED

18/05/2017GDPR Explained36

Page 37: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Why encryption?

Lost or stolen data in terms of GDPR

Only breach notification

No user information duty

No secrets revealed

No bad publicity

Less business impact

Breach prevention

18/05/2017GDPR Explained37

Page 38: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Top HSM Use Cases

Public Key Infrastructure

Transparent Data Encryption

SSL/TLS Private Key Protection

Code Signing

Data Protection for Cloud Apps

18/05/2017GDPR Explained38

Page 39: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

TDE ProtectFile

ProtectFileProtectApp

Files, Folders, or Shares

WHERE DOES THE SENSITIVE DATA RESIDE?

File Level

Databases

Selected

Columns

Whole

Database Files

App

Level

ProtectV

App

Level

Block Level

File

System

Level

TokenizationProtectApp

Encrypt Tokenize

ProtectDB

Database

Level

The correct connector … for every use-case

18/05/2017GDPR Explained39

Page 40: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Tokenization

ProtectVProtectFile

ProtectApp

KeySecure Platform

Distributed Key Management

ProtectDB

• Key and crypto engine

• Authentication and authorization

• Key lifecycle management

• SNMP, NTP, SYSLOG

File Servers

& SharesWeb & Application

Servers

DatabasesApplication

ServersVirtual Machines

KeySecure Platform

18/05/2017GDPR Explained40

Page 41: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Data Controller / Processor

18/05/2017GDPR Explained41

SaaSSoftware-as-a-service

PaaSPlatform-as-a-service

IaaSInfrastructure-as-a-service

Data Flow

Application

Database

File / OS

Virtual Machine

Processor

Processor

Processor

Controller

Processor

Processor

Controller

Processor

Contr. / Proc. Controller

Controller

Processor

ProtectApp | Tokenization | FPE | PKCS#11 ProtectApp | Tokenization | FPE | PKCS#11 ProtectApp | Tokenization | FPE | PKCS#11

ProtectDB | TDE (Native DB Encryption) ProtectDB | TDE (Native DB Encryption) ProtectDB | TDE (Native DB Encryption)

ProtectFile | KMIP | PreBoot Enc. | Full Disk Enc. ProtectFile | KMIP | PreBoot Enc. | Full Disk Enc. ProtectFile | KMIP | PreBoot Enc. | Full Disk Enc.

ProtectV | KMIP ProtectV | KMIP ProtectV | KMIP

Page 42: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Key Management

GDPR EXPLAINED

18/05/2017GDPR Explained42

Page 43: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Why Key Management?

No direct GDPR compliancy requirement

BUT when encrypting data:

Data is no longer important

But Key Management is!

18/05/2017GDPR Explained43

Page 44: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Central key management

18/05/2017GDPR Explained44

Page 45: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

A new mindset

KeySecure or

Virtual KeySecure

Luna HSM or

Cloud HSM

Crypto Command Center

SafeNet Data Encryption Solutions / Crypto Management Platform

Doc

Signing

SSL

Webserver

Email

Gateway

Payment

Transactions

File & Disk

Encryption

Customer

KMIP Client

Backup,

Storage &

Archive

SIEM Tools

Cloud Storage

& Encryption

Gateways

ProtectApp ProtectFile ProtectDB StorageSecure ProtectV™Ethernet

Encryption

Tokenization

Manager

18/05/2017GDPR Explained45

Page 46: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Summary

GDPR EXPLAINED

18/05/2017GDPR Explained46

Page 47: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Crypto

Management

Key

Manager

HSM

Crypto

Provisioning

System

SECURE &

MANAGE KEYS

3

Applications

SaaS

Apps

Internal Users +

Administrators

Cloud Providers

Admins/Superuse

rs

Internal Users +

Administrators

Cloud Providers

Admins/Superuse

rs

Strong Authentication

CONTROL

ACCESS

Internal Users +

Administrators

Cloud Providers

Admins/Superusers

Customers +

Partners

1

Summary

File Servers

Database

s

Virtual Machines

Storage Networks Physical Data Virtual Data Data in the Cloud

ENCRYPT THE DATA

Data at Rest Encryption Data in Motion Encryption2

18/05/2017GDPR Explained47

Page 48: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

400+Authentication

Integrations

300+HSM

Integrations

30+KeySecure

Integrations

35+Crypto

Integrations

18/05/2017GDPR Explained48

Page 49: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

+300HSM

Integrations

400+Authentication

Integrations

300+HSM

Integrations

30+KeySecure

Integrations

35+Crypto

Integrations

18/05/2017GDPR Explained49

Page 50: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

+300HSM

Integrations

400+Authentication

Integrations

300+HSM

Integrations

30+KeySecure

Integrations

35+Crypto

Integrations

18/05/2017GDPR Explained50

Page 51: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

400+Authentication

Integrations

300+HSM

Integrations

30+KeySecure

Integrations

35+Crypto

Integrations

18/05/2017GDPR Explained51

Page 52: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Questions?

GDPR EXPLAINED

18/05/2017GDPR Explained52

Page 53: GDPR Explainedsentia.events/files/GDPR-Explained_2017 - Sentia.pdfGDPR Legislation Translate GDPR for your specific situation Go and read the legislation: English Dutch French NOTE:

Thank you

GDPR EXPLAINED

18/05/2017GDPR Explained53