GDPR: 5 Lessons Learned Veeam Compliance Experience Shared a Step-By-Step Guide for IT Professionals
Total Page:16
File Type:pdf, Size:1020Kb
GDPR: 5 Lessons Learned Veeam Compliance Experience Shared A Step-by-Step Guide for IT Professionals Mark Wong General Counsel © 2018 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. GDPR: 5 lessons learned, Veeam compliance experience shared. Contents Introduction ............................................................................................................ 3 Know your data ......................................................................................................... 4 Manage the data ........................................................................................................ 6 Location . 7 Who has access? . 10 Exclusions . 11 Protect the data ........................................................................................................ 11 Documenting and complying ........................................................................................... 14 Continuous improvement .............................................................................................. 15 Conclusion .............................................................................................................. 15 About Veeam Software ................................................................................................. 16 © 2018 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 1 GDPR: 5 lessons learned, Veeam compliance experience shared. Veeam® is committed to sharing our GDPR compliance experience with you . This regulation is complex and fact specific, meaning each organization’s GDPR compliance program may mean something different from the next company . GDPR is a major update to the Data Protection Directive from 1995, or more specifically 95/46/EC (that’s right, over 21 years between major releases!), and the data intensive world we live in is significantly different than the world we lived in in 1995 . Many people might think that the GDPR is just an IT issue, but that is the furthest from the truth . It affects everyone — not just IT . We have prepared this white paper as a discussion of how Veeam interprets GDPR as of the date of publication . As a privately held information technology company that develops backup, disaster recovery and data management software for virtual, physical and cloud-based workloads to provide Availability for the Always-On Enterprise™, we have spent a lot of time with GDPR not only complying with it as a global organization, but also in development of our products . This white paper should not be relied upon as legal advice or determination on how GDPR applies to your organization . We encourage you to do as we did and work with legally qualified professionals to discuss GDPR and how it applies to your organization and collaborate and build a plan towards compliance . Veeam provides this white paper “as-is” and makes no warranties, express or implied as to the information in this white paper . Published on January 2018. Version 1.0 © 2018 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 2 GDPR: 5 lessons learned, Veeam compliance experience shared. Introduction In mid-2016, shortly after the enactment of the General Data Protection Regulation, or GDPR, Veeam’s executive management team immediately invested in a GDPR compliance initiative . We recognized that GDPR is the new benchmark and global standard that other countries will look to as a standard for data privacy . GDPR is brand new law and the first law addressing data privacy of individuals since the Data Protection Directive 95/46/EC . It’s a broad sweeping law and we encourage you to read it, all 260 pages of it found here at: http://data consilium. europa. eu/doc/document/ST-5419-2016-INIT/en/pdf. The first tip we can provide you is to embrace the fact that this is an “evolution” not a “revolution” as many of your organizational practices you had before in compliance with the Data Protection Directive serve as the foundation for GDPR compliance . You will find numerous articles and blog posts talking about GDPR as organizations are scrambling to leverage this opportunity to grab your attention . We here at Veeam think very thoroughly . We have been building software solutions to help organizations like yours operate more efficiently and effectively . Our founders, Ratmir Timashev and Andrei Baronov founded Aelita software, a company that provided enterprise network management tools that improved security, usability and control over an organization’s network environments . You can still find these tools in Quest Software’s Windows Management products . Mr . Timashev and Baronov launched Veeam in 2006 and with our Veeam Availability Platform, we enable organizations like yours to ensure Availability for any application, any data, across any cloud . We know data management and data protection, two (2) of the key principles behind GDPR and we want to walk you through what GDPR means for us and how our products can help you address the key principles of GDPR . The Veeam game plan is to approach GDPR compliance by addressing the following five (5) principles: 1. Know your data: Identify the Personally Identifiable Information (“PII”) your organization collects, has and who has access; 2. Manage the data: Establish the rules and processes to access and use PII 3. Protect the data: Implement and ensure security controls are in place to protect the information and respond to data breaches 4. Documenting and Complying: Document your processes, execute on data requests and report any issues or data breaches within the guidelines 5. Continuous Improvement: Keep up with the fast-changing digital world and constantly review and improve your processes and procedures for data privacy and protection © 2018 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 3 GDPR: 5 lessons learned, Veeam compliance experience shared. Know your data If your organization has PII, then you need to find out where ALL of it is and how you collect it . GDPR is an organization- wide effort and everyone must be involved . If your organization has PII of an EU resident, then GDPR applies to you . If your organization is located in the European Economic Area, then GDPR applies to you . GDPR is the new benchmark and standard for data privacy and is seen as the “global leader” . We at Veeam expect many of the concepts to be implemented by other countries very soon . So even if you are the rare organization that doesn’t believe GDPR applies to you, the concepts will eventually apply to you once its adopted by your local jurisdiction . We believe sharing what we learned will help you in your compliance process . We are a global company, Swiss headquartered, with a truly global footprint and have 3,000 employees all over the world . Not only do we have customers all over the world, many of our customers share the same global footprint that we do . Accordingly, Veeam is a global data controller and we not only comply with GDPR, we are constantly driving to implement best practices for GDPR and data privacy compliance in general . As we are committed to sharing our compliance initiative with you, we are also committed to providing the materials that we developed internally in our journey to date . As already said, finding out where ALL your data is, how you collect it, who has access to it and where you (physically) keep that data is the first step in your journey to compliance . Top tip: Flow charts mapping the flow of PII across your organization and to your third-party partners is a valuable way to get started. A visual map is a great way to classify and manage your network environments and we will show you how Veeam has designed helpful environment mapping tools in its Veeam Availability Platform to give you an entire picture of your environment. Figure 1: Example of infrastructure data map © 2018 Veeam Software. Confidential information. All rights reserved. All trademarks are the property of their respective owners. 4 GDPR: 5 lessons learned, Veeam compliance experience shared. As an organization, after completing the first step, you’ve probably classified your data and identified all of the various locations that PII is stored . There are certain VM’s, physical servers or even cloud instances for HR, mailboxes, that you know contain PII . Often times, this information is also business critical and core to the operations of your company . You need this data available so you have a backup plan for these environments . If you’re already using Veeam, then you know about how Veeam ONE™ 9 .5 offers you complete visibility into your backup and virtual environments . Figure 2: Example of a dashboard for your backup infrastructure With Veeam ONE 9 .5, you have a powerful monitoring, reporting and capacity planning tool for your backups, VMWare vSphere, Microsoft Hyper-V VM’s, physical servers, workstations and cloud VM’s . You can rest assured if you have structured your environments for GDPR compliance, your backups are also stored and managed in a logical way where you have complete visibility into the environments at all times . You can control and manage your backup plan to be synergistic with your operating VM’s, knowing if you need your backup, it will be available . © 2018 Veeam Software. Confidential information. All rights reserved.