Framework of preparation with the new EU regulation (2016/679) for the protection of personal data
Πλαίσιο προετοιμασίας για το νέο κανονισμό της ΕΕ (2016/679) για την προστασία των προσωπικών δεδομένων
View/ Open
Keywords
Πλάνο εργασιών ; ISMS ; Compliance ; Big data ; GDPR 2016/679 ; Project plan ; Gap analysis ; SecurityAbstract
The “big data” future has undoubtedly arrived. Everyday a vast amount of information about a person’s life is created and made available through the use of their devices. Personal data such as their address, phone number, political opinions, sex life, racial or ethnic origin and medical or banking details are made available to persons and corporations, with consent in most of the cases. Those entities can use the personal data for specified and lawful purposes. In many cases though, personal data can be misused and for that reason data protection has become a matter of vital importance. To address this matter, the European Parliament, the Council of the European Union and the European Commission joined forces and compiled the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) in order to strengthen and unify data protection for all individuals within the European Union. This master’s thesis deals with the challenges that the EU faces to address as data privacy issues and data breaches, the comparison between the GDPR 2016/679 and the previous EU Directive 95/46/EC and also the creation of a preparation framework that describes all the necessary processes that need to be implemented from an entity so that it is compliant with this new regulation. The aforementioned preparation framework will help the institutions to understand the new rules, get informed on the regulatory fines if they fail to comply with the new regulation, plan the necessary actions to be performed so that the institution is compliant with the new regulation, execute these actions through a detailed work plan/road map and clear guidelines. At the end of this process, the institution will be compliant to the GDPR 2016/679 having saved a lot of time and effort.