Listen to this episode

Petronella Technology Group Podcast 01-14-21

0:0049:30

Recorded January 2021. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig Petronella of Petronella Technology Group welcomes Lisa Shastine, co-founder of the Shastine and Percy Law Firm in Tampa, Florida, a practice focused entirely on data security and privacy. Lisa explains that the General Data Protection Regulation took effect in May 2018 and grew out of Europe's long-standing treatment of privacy as a fundamental right.

She recalls a client data breach days later that triggered what she describes as a 72-hour reporting deadline at the time of recording. The conversation covers the distinction between data controllers and data processors, the broad definition of personal data, and the lawful bases for processing, such as consent and contract performance. Lisa explains when United States businesses may fall under GDPR, including targeted marketing in European languages or currencies, and notes that GDPR covers nonprofits while, at the time of recording, California's CCPA does not. She recommends starting with a data map, performing data privacy impact assessments, and using encryption. She also describes how, at the time of recording, the Schrems Two decision had invalidated the Privacy Shield, leading companies toward standard contractual clauses for transatlantic data transfers.

Worth remembering

Key takeaways

  1. Lisa advises first determining whether people in EEA countries regularly access your services, because knowingly doing business with them creates a duty to examine GDPR requirements.
    “Do you know that people in these countries are accessing, you know, your your services or your products?”
  2. Lisa recalls a client breach just after GDPR took effect that triggered what she describes as a 72-hour reporting deadline at the time of recording.
    “they had the obligation of reporting their data breach within 72 hours of discovery of that breach.”
  3. Lisa explains that processing is lawful only if at least one basis applies, such as consent, contract performance, a legal obligation, or legitimate interest.
    “the data subject has given consent to the processing of his or her personal data for one or more specific purposes. So there's your consent, right?”
  4. Lisa notes that GDPR protects a much broader range of information than United States law, including opinion data, which is not protected in the United States.
    “Opinion data under the GDPR is a protected category of information.”
  5. Lisa warns that translating pricing into GDPR country currencies or marketing in local languages could be seen as doing business in Europe.
    “So you're translating your pricing into into GDPR country currencies. You are translating it into their languages or the languages most used in in those countries.”
  6. Lisa suggests starting with a data map of your own business processes, then analyzing it through the lens of GDPR and performing a data privacy impact assessment.
    “That's why I'm suggesting you start with your data map and just your own business processes.”
  7. Lisa calls encryption a fabulous tool and a get-out-of-jail-free card in most every jurisdiction, provided the implementation, such as hashing, is strong enough.
    “encryption is a fabulous tool; it's a get-out-of-jail-free card in most every jurisdiction.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Petronella Technology Group Podcast 01-14-21 with Craig Petronella of Petronella Cybersecurity and Digital Forensics and Expert GDPR Attorney Lisa Shasteen discuss what GDPR is and steps you can take to make your website and business compliant.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.