0%

Book Description

A concise introduction to EU GDPR and EU-US Privacy Shield The EU General Data Protection Regulation will unify data protection and simplify the use of personal data across the EU when it comes into force in May 2018. It will also apply to every organization in the world that processes personal information of EU residents. US organizations that process EU residents' personal data will be able to comply with the GDPR via the EU-US Privacy Shield (the successor to the Safe Harbor framework), which permits international data transfers of EU data to US organizations that self-certify that they have met a number of requirements. EU GDPR & EU-US Privacy Shield – A Pocket Guide provides an essential introduction to this new data protection law, explaining the Regulation and setting out the compliance obligations for US organizations in handling data of EU citizens, including guidance on the EU-US Privacy Shield. Product overview EU GDPR & EU-US Privacy Shield – A Pocket Guide sets out: A brief history of data protection and national data protection laws in the EU (such as the UK DPA, German BDSG and French LIL). The terms and definitions used in the GDPR, including explanations. The key requirements of the GDPR, including: Which fines apply to which Articles; The six principles that should be applied to any collection and processing of personal data; The Regulation’s applicability; Data subjects’ rights; Data protection impact assessments (DPIAs); The role of the data protection officer (DPO) and whether you need one; Data breaches, and the notification of supervisory authorities and data subjects; Obligations for international data transfers. How to comply with the Regulation, including: Understanding your data, and where and how it is used (e.g. Cloud suppliers, physical records); The documentation you need to maintain (such as statements of the information you collect and process, records of data subject consent, processes for protecting personal data); The “appropriate technical and organizational measures” you need to take to ensure your compliance with the Regulation. The history and principles of the EU-US Privacy Shield, and an overview of what organizations must do to comply. A full index of the Regulation, enabling you to find relevant Articles quickly and easily.

Table of Contents

  1. Cover
  2. Title
  3. Copyright
  4. ABOUT THE AUTHOR
  5. CONTENTS
  6. Introduction
  7. Chapter 1: A Brief History of Data Protection
  8. Chapter 2: Terms and Definitions
  9. Chapter 3: the Regulation
    1. Principles
    2. Applicability
    3. Data subjects’ rights
    4. Consent
    5. Right to be forgotten
    6. Data portability
    7. Lawful processing
    8. Retention of data
    9. The “one-stop shop”
    10. Records of data processing activities
    11. Data protection impact assessments
    12. Data protection by design and by default
    13. Controller/processor contracts
    14. The data protection officer
    15. Accountability and the Board
    16. Data breaches
    17. Encryption
    18. International transfers
    19. Binding corporate rules
    20. Additional considerations
    21. Changes to the ‘Cookies Law’
    22. IP addresses
    23. The EU Network and Information Security (NIS) Directive
  10. Chapter 4: Complying with the Regulation
    1. Repercussions
    2. Understanding your data: where it is and how it is used
    3. Documentation
    4. Appropriate technical and organisational measures, ISO/IEC 27001 and ISO/IEC 27018
    5. Standards, schemes and trust seals
    6. Securing supplier relationships
  11. Chapter 5: EU-US Privacy Shield
  12. Chapter 6: Index of the Regulation
  13. Appendix 1: National Data Protection Authorities
  14. Appendix 2: EU GDPR Resources
  15. ITG Resources