52
Senior Director - Security Architecture, WSO2 General Data Protection Regulation (GDPR) for Identity Architects Prabath Siriwardena

GDPR for Identity Architects

Embed Size (px)

Citation preview

Page 1: GDPR for Identity Architects

Senior Director - Security Architecture, WSO2

General Data Protection Regulation (GDPR) for Identity Architects

Prabath Siriwardena

Page 2: GDPR for Identity Architects

GDPR OVERVIEW

Page 3: GDPR for Identity Architects
Page 4: GDPR for Identity Architects
Page 5: GDPR for Identity Architects
Page 6: GDPR for Identity Architects
Page 7: GDPR for Identity Architects
Page 8: GDPR for Identity Architects
Page 9: GDPR for Identity Architects
Page 10: GDPR for Identity Architects
Page 11: GDPR for Identity Architects
Page 12: GDPR for Identity Architects
Page 13: GDPR for Identity Architects
Page 14: GDPR for Identity Architects

14

Page 15: GDPR for Identity Architects

15

DATA PROTECTION IMPACT ASSESSMENT (DPIA)

● Following activities are required to have a DPIA○ Processing of special categories of personal data at large scale.○ Core business activities consist of systematic monitoring of the data subject at

large scale.○ Monitoring of publicly accessible areas at a large scale

Page 16: GDPR for Identity Architects

16

Page 17: GDPR for Identity Architects

17

Page 18: GDPR for Identity Architects

18

Page 19: GDPR for Identity Architects

19

DATA PROCESSING RECORD (CONTROLLER)

● Name and contact details of controllers, the representatives, and data protection officer.

● Purposes of processing● Description of the categories of data subjects and categories of personal data.● The categories of recipients to whom the personal data have need or will be

disclosed.● Transfers of personal data to a third country/international organization.● Time limits for the erasure of the different data categories.● General description of the technical and organizational security measures.

Page 20: GDPR for Identity Architects

20

Page 21: GDPR for Identity Architects

21

DATA PROCESSING RECORD (PROCESSOR)

● Name and contact details of controllers, the representatives, and data protection officer.

● Categories of processing● Transfers of personal data to a third country/international organization.● General description of the technical and organizational security measures.

Page 22: GDPR for Identity Architects

22

Page 23: GDPR for Identity Architects

23

Page 24: GDPR for Identity Architects

24

Page 25: GDPR for Identity Architects

25

Page 26: GDPR for Identity Architects

26

Page 27: GDPR for Identity Architects

27

Page 28: GDPR for Identity Architects

28

Page 29: GDPR for Identity Architects

29

Page 30: GDPR for Identity Architects

DATA SUBJECT’S RIGHTS

Page 31: GDPR for Identity Architects

31

Page 32: GDPR for Identity Architects

32

Page 33: GDPR for Identity Architects

33

Page 34: GDPR for Identity Architects

34

Page 35: GDPR for Identity Architects

35

Page 36: GDPR for Identity Architects

36

Page 37: GDPR for Identity Architects

37

Page 38: GDPR for Identity Architects

IAM DESIGN PRINCIPLES AND

BEST PRACTICES

Page 39: GDPR for Identity Architects

39

Page 40: GDPR for Identity Architects

40

Page 41: GDPR for Identity Architects

41

Page 42: GDPR for Identity Architects

42

FACEBOOK COOKIE POLICYhttps://www.facebook.com/policies/cookies/

Page 43: GDPR for Identity Architects

43

GOOGLE COOKIE POLICYhttps://www.google.com/policies/technologies/cookies/

Page 44: GDPR for Identity Architects

44

Page 45: GDPR for Identity Architects

45

FACEBOOK DATA USE POLICYhttps://www.facebook.com/full_data_use_policy

Page 46: GDPR for Identity Architects

46

Page 47: GDPR for Identity Architects

47

Page 48: GDPR for Identity Architects

48

Page 49: GDPR for Identity Architects

49

Page 50: GDPR for Identity Architects

50

Page 51: GDPR for Identity Architects

51

Page 52: GDPR for Identity Architects

wso2.com

52