CanInnovate

E28: Insiders Guide to GDPR & turning it into a competitive advantage with Dr. Ann Cavoukian


Listen Later

What is GDPR? How to turn GDPR into our next competitive advantage & avoid the penalties!

Today, we are talking about General Data Protection Regulation (GDPR) and the due date for businesses to be compliant is fast approaching.. May 25th, 2018.  

We chat with Dr. Ann Cavoukian who gives us the low-down on the importance of GDPR, the relevance, the implications and some tools that will enable us to be prepared and turn this into our next competitive advantage.

Dr. Ann Cavoukian is recognized as one of the world's leading privacy experts. She is currently the Distinguished Expert-in-Residence, leading the Privacy by Design Centre of Excellence at Ryerson University. Her Privacy by Design framework is now the International Standard and has been translated into 39 languages. Dr. Ann Cavoukian has won numerous awards such as Top 25 Women of Influence in Canada Top 10 Women in Data Security & Privacy, Power 50 by Canadian Business, Top 100 Leaders in Identity.

 

Some highlights:

  • 40% of companies of are prepared for GDPR
  • GDPR will be very positive if you can get ahead of it
  • 92% of consumers are concerned about their privacy and loss of control
  • Consumers don’t want this lack of control
  • Lead by telling your customers that you’re protecting their privacy
  • Make it a win-win prospect, this will build loyalty and customer trust
  • GDPR applies to all 28 EU member countries
  • It’s one overarching regulation
  • GDPR raises privacy dramatically and includes privacy by design
  • Privacy by design is the strongest form of privacy protection because it’s proactive
  • Medical model of prevention
  • Privacy by default, which is the 2nd privacy by design principle is included in GDPR
  • Currently, we need to opt-out, but it’s going to change
  • It says that the companies need to get customer’s positive consent
  • Need to make it clear on how we collect people’s information, what purpose they use it for and the ways in which they process the data
  • Review what you are doing now, identify what customer information that you’re acquiring
  • Consumers now have the right to have their data deleted at any time if they feel that is not required
  • Each element of data collected needs to have a clear purpose and intent, in which consumers have provided their permission
  • Need to get the consent from the customer - need to seek their positive consent
  • Penalties - 4% of your global revenues
  • Imagine 4% of Facebook or Google - it’s going to be billions
  • GDPR is the starting point, but it will impact everyone globally
  • Everyone wants to do business with the EU
  • In Canada, our privacy legislation was pretty good, but now, it’s no now longer adequate. Canadian laws are going to be updated in order to be adequate and consistent with GDPR
  • Personal data is defined as any identifiable information - this includes IP addresses, locations, cookies, preferences etc.. Article: GDPREU.ORG - personal data https://www.gdpreu.org/the-regulation/key-concepts/personal-data/
  • Do Privacy by Design - do the 7 principles and it will show that you are acting in good faith the be compliant
  • GDPR has been in the process for 5 years, so companies have had lots of time to get ready for May 25th, 2018 deadline
  • GDPR is going to take a hard line on this
  • You can have privacy and marketing and give consumer options
  • Need to revalidate with your existing customers of which data they should be using
  • Shouldn’t be using and keeping personal data forever, we should be purging
  • Security breaches are becoming more and more common

Tools:

  • ICO.Org.UK - 12 Steps to take now - https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf
  • Privacy by Design - Seven Foundational Steps - https://www.ryerson.ca/pbdce/certification/seven-foundational-principles-of-privacy-by-design/
  • Data Protection Self Assessment - https://ico.org.uk/for-organisations/resources-and-support/data-protection-self-assessment/
  • Direct Marketing Checklist - https://ico.org.uk/for-organisations/resources-and-support/data-protection-self-assessment/direct-marketing-checklist/ 
  • EU GDPR - https://www.eugdpr.org/
  • Article: Data Privacy deadline looms in EU, and yes, Canadian business must comply http://business.financialpost.com/executive/many-canadian-organizations-unprepared-for-the-eus-gdpr-compliance-deadline
  • ITPRO Article: GDPR Preparation: 2018 data protection changes - http://www.itpro.co.uk/security/27563/how-to-get-ready-for-gdpr-2018-data-protection-changes/page/0/2
  • Article: GDPREU.ORG - Personal Data https://www.gdpreu.org/the-regulation/key-concepts/personal-data/

I even published a blog about GDPR CanInnovate Blog

Check out our new website - NEW WEBSITE: www.CanInnovate.io 

CanInnovate also has a new resources & tools page, that provides different offers and discounts. Who doesn't love to save money? http://caninnovate.io/offers/ 

Thanks again for tuning in! Would love to hear/read your thoughts and feedback. If you get a minute, perhaps even leave a review:) I'm still channelling Gary Vee! Ratings and reviews are my oxygen!:)

Talk to you all next week.

Best Always, Sapna

[email protected] 

...more
View all episodesView all episodes
Download on the App Store

CanInnovateBy Sapna Malhotra: Always Curious at the School of Life

  • 5
  • 5
  • 5
  • 5
  • 5

5

8 ratings