My First Taste of GDPR

It is no secret that I am, for lack of a better term, a nerd. I am also a Privacy Consultant here at Privacy Ref, so I usually pride myself on knowing about privacy goings on in the world. However, for the first time I was bamboozled by changes to a privacy policy.

Defining GDPR for Non-Privacy People

During the IAPP’s most recent Privacy Summit, I was approached with an interesting question. “I am a privacy professional and I know why GDPR is important. I know about the fines and requirements for compliance, but few others at my company do. How do I explain GDPR to my colleagues effectively?”...

Breach Notification and Follow Up

Unfortunately, it is a given that as an organization you will receive a notice from a third party that they had an incident or breach that may have compromised personal or sensitive employee or customer information.  A majority of the breach laws require immediate notification or notification wit...

Top 6 Things For GDPR Procrastinators To Do

May has many holidays; Mothers Day, Memorial Day, Cinco de Mayo, Star Wars Day (May the fourth), and, of course, the new GDPR Day. Almost everyone is ready for the first four, but we continue to get calls from those GDPR procrastinators to help them prepare. With less than a month left to GDPR Da...

Facebook and Trust

I have previously written about the importance of a privacy program to in part, manage trust between an organization and its customers. As more data breaches occur and privacy is made more of an issue that is embraced and examined by the general public, this trust will become more important. One ...

Is Your Response Plan Responsive Enough?

So, you have a formal data breach response plan in place or an informal plan of action in mind….now what?  With Alabama and South Dakota in a race to become the 49th state to enact data breach notification legislation (for sure, no one wants to be the “last man standing” in this scenario!),...

Looking forward to the IAPP Global Privacy Summit

It’s that time of year again; time for the IAPP’s Global Privacy Summit. Yes, I pack up this weekend to head to Washington, DC for training, seminars and, of course, networking.

Do It Your Self Rights Requests

On our last webinar (as of this writing) I discussed how a company can handle data subject’s rights requests under GDPR. Many of these requests are going to require attention, such as those ‘right to be forgotten’ requests. Others may seem daunting but can be handled easily and may not require an...