presentación de powerpoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia...

34
AEPD TOOLS https://www.aepd.es/herramientas/index.html Andrés Calvo Unit of technological studies and assessments

Upload: others

Post on 11-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

AEPD TOOLS

https://www.aepd.es/herramientas/index.html

Andrés Calvo

Unit of technological studies and assessments

Page 2: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón TOOLS REQUIRED

https://www.aepd.es/herramientas/index.html

Page 3: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

RISK LEVELS

NEED ANALYSIS

NEEDED?

No

NO-NEED REPORT

PERSONAL DATA LIFE CYCLE ANALYSIS

lawfullness, proportionality and need of data processing

PERSONAL DATA LIFE CYCLE ANALYSIS

Action Plan Conclusions

Risk management (1)

Risk Management (2)

Residual risk OK?

ART. 36 GDPR

CONTROL AUTHORITY

Action Plan Conclusions

No yes

FACILITA

PIA: HIGH RISK

RISK ANALYSIS

DATA PROCESSING

LOW RISK

(1) Basic measures

(2) Advances measures

PROTECTION:

Page 4: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón TOOLS REQUIRED

https://www.aepd.es/herramientas/index.html

Page 5: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

• MICROENTERPRISES (9 or less employees).

• MOST COMMON DATA PROCESSING: – LOW RISK TO THE RIGHTS AND FREEDOMS OF NATURAL

PERSONS – CUSTOMERS / SUPPLIERS – PAYROLL MANAGEMENT, STAFF, HUMAN RESOURCES – VIDEO SURVEILLANCE

• USEFUL FOR ANY LOW RISK PROCESSING

FACILITA INITIAL FOCUS

Page 6: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

• IMPLEMENTATION OF SEVERAL SPANISH DATA PROTECTION AGENCY GUIDELINES:

– GUIDELINES FOR DATA CONTROLLERS

– GUIDELINES FOR THE DUTY TO INFORM

– GUIDELINES ON CONTRACT CLAUSES FOR PROCESSORS

Page 7: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

• ASSIST THE CONTROLLERS IN THE ELABORATION OF:

– REGISTRY OF DATA PROCESSING ACTIVITIES

– INFORMATION CLAUSES FOR DATA SUBJECTS

– CONTRACTUAL CLAUSES FOR DATA PROCESSORS

– BASIC TECHNICAL AND ORGANIZATIONAL MEASURES

Page 8: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

DISCARD RISKY PROCESSING

CASES

COLLECT CONTROLLER

INFORMATION

COLLECT PROCESSING

DETAILS

GENERATE OUTCPUT

DOCUMENTS

• OPERATING PHASES:

Page 9: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

DISCARD RISKY PROCESSING

CASES

Page 10: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

DISCARD RISKY PROCESSING

CASES

Page 11: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

DISCARD RISKY PROCESSING

CASES

Page 12: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

COLLECT CONTROLLER

INFORMATION

Page 13: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

COLLECT PROCESSING

DETAILS

CUSTOMERS/CLIENTS DATA PROCESSING

Page 14: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

COLLECT PROCESSING

DETAILS

EMPLOYEES DATA PROCESSING, …

Page 15: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

GENERATE OUTPUT

DOCUMENT

Page 16: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

• IMPORTANT NOTE: DISCLAIMER

– FACILITA_RGPD USAGE DOES NOT GURANTEE GDPR COMPLIANCE, IT IS JUST AN AID

– SPANISH DATA PROTECTION AGENCY DOES NOT STORE ANY DATA COLLECTED, DATA IS DELETED AFTER OUTCOME DOCUMENTS ARE GENERATED

Page 17: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

https://www.servicios.agpd.es/Facilita

Page 18: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

FACILITA RGPD

Page 19: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

RISK LEVELS

NEED ANALYSIS

NEEDED?

No

NO-NEED REPORT

PERSONAL DATA LIFE CYCLE ANALYSIS

Legitimación, necesidad y proporcionalidad del tratamiento

PERSONAL DATA LIFE CYCLE ANALYSIS

Action Plan Conclusions

Risk management (1)

Risk Management (2)

Residual risk OK?

ART. 36 GDPR

CONTROL AUTHORITY

Action Plan Conclusions

No yes

FACILITA

EIPD: HIGH RISK

RISK ANALYSIS

DATA PROCESSING

LOW RISK

(1) Basic measures

(2) Advances measures

PROTECTION:

Page 20: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón TOOLS REQUIRED

https://www.aepd.es/herramientas/index.html

Page 21: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón TOOLS REQUIRED

https://gestiona.aepd.es/

Page 22: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

RISK ANALYSIS

GESTIONA EIPD/PIA

Page 23: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

RISK ANALYSIS

GESTIONA EIPD/PIA

PERSONAL DATA LIFE CYCLE

COLLECTING DATA

STORING DATA

USING DATA THIRD

PARTIES DATA TRANSFERS

DESTROYNG DATA

• OPERATING PHASES:

Page 24: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

RISK ANALYSIS

GESTIONA EIPD/PIA

RISK MANAGEMENT

IDENTIFICATE EVALUATE MITIGATE

• OPERATING PHASES:

Page 25: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

PIA

GESTIONA EIPD/PIA

Page 26: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

PIA

GESTIONA EIPD/PIA

NEED ANALYSIS

AUTHORITIES LISTS SENSIBLE DATA

PURPOSE OF DATA

TECHNOLOGIES INVOLVED

THIRD PARTIES DATA TRANSFERS

RISK PERCEPTION LAWFULNESS

• OPERATING PHASES:

Page 27: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

PIA

GESTIONA EIPD/PIA

PERSONAL DATA LIFE CYCLE

COLLECTING DATA

STORING DATA

USING DATA THIRD

PARTIES DATA TRANSFERS

DESTROYNG DATA

• OPERATING PHASES:

Page 28: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

PIA

GESTIONA EIPD/PIA

LAWFULNESS ASPECTS

CONSENT CONTRACTS LEGAL DUTY PUBLIC INTEREST

LEGITIMATE INTEREST

• OPERATING PHASES:

Page 29: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

PIA: RISK ANALYSIS

GESTIONA EIPD/PIA

RISK MANAGEMENT

IDENTIFY EVALUATE MITIGATE

• OPERATING PHASES:

Page 30: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

PIA: RISK ANALYSIS

GESTIONA EIPD/PIA

• OPERATING PHASES: OUTPUT

Page 31: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

METHODOLOGY

- 29WG/EDPB GUIDELINES - AEPD GUIDELINES - ISO: 31000:2010, 31010:2010, 29134:2017

GESTIONA EIPD/PIA

Page 32: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

NEXT STEPS:

GESTIONA EIPD/PIA

Page 33: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

Haga clic para modificar el estilo de título del patrón

WORKGROUP ON PIA AND RISK ANALYSIS

GESTIONA EIPD/PIA

SPANISH PUBLIC ADMINISTRATION WORKGROUP ON PRELIMINARY IMPACT ASSESSMENTS AND RISK

ANALYSIS:

• AEPD

• LABOUR MINISTRY

• INFORMATION TECHNOLOGY MANAGEMENT FOR THE SOCIAL SECURITY

Page 34: Presentación de PowerPoint · 2019-12-03 · workgroup on pia and risk analysis gestiona eipd/pia spanish public administration workgroup on preliminary impact assessments and risk

34