Understand current legal and regulatory issues in IT -Data Protection- Dr. Fatma Ben Mesmia [email protected]
Activity Legislation, Regulation, Ethics and Codes of Practice 2 Activity Divide into groups to prepare and conduct interviews with each other The focus of these interviews will be on assessing the knowledge about cybersecurity practices and the legislation that organizes and regulates the cybersecurity sector
Data Protection Legislation, Regulation, Ethics and Codes of Practice 3 Laws , regulations & standards relating to personal data and privacy What is data privacy? Data privacy is a component of data protection Better data use Improve business reputation Lower storage costs Regulatory compliance Technologies for Data Privacy: Access control-Two-factor authentication- Encryption What are the challenges of data privacy? Poor data visibility Too many devices Excessive number of rules
Data Protection Legislation, Regulation, Ethics and Codes of Practice 4 Laws , regulations & standards relating to personal data and privacy e.g. General Data Protection Regulation (GDPR) a regulation that requires businesses to protect their personal data Fines and penalties for non-compliance Six Steps to Ensure GDPR Compliance Understand the GDPR law Examine Other Organizations Classify Data, Mark Regulated Data Pay Particular Attention to the Company Website Pay Particular Attention to Your Data Revise and Audit
Data Protection Legislation, Regulation, Ethics and Codes of Practice 5 Use of digital systems (e.g. Computer Misuse Act 1990) digital system Computer Misuse Act 1990 law relates to electronic records in that it creates three crimes of illegal access to computer software
Data Protection Legislation, Regulation, Ethics and Codes of Practice 6 Regulatory standards for cyber security, intelligence collection, and law enforcement Intelligence Services Act 1994 Regulation of Investigatory Powers Act 2000 Standards for good practice in cyber security (e.g. ISO 27001, CyberEssentials , NIST )
Data Protection Legislation, Regulation, Ethics and Codes of Practice 7 Regulatory standards for cyber security, intelligence collection, and law enforcement
Data Protection Legislation, Regulation, Ethics and Codes of Practice 8 Impact of legislation in HCI design Accessibility: Americans with Disabilities Act (ADA) Privacy and Data Protection (GDPR) Security: Health Insurance Portability and Accountability Act (HIPAA ) User Rights and Transparency