The complexities of implementing the General Data Protection Regulation (GDPR) continue to grow as it progresses through new and ever-changing technologies, business models, codes of conduct, and decisions of the supervisory authorities, and the courts. This eminently practical guide to implementing the GDPR - written in an original, problem-solving style by a highly experienced data protection expert with equal knowledge of both law and technology - provides a step-by-step project management approach to building a GDPR-compliant data protection system, assessing, and documenting the risks and then implementing these changes through processes at the operational level.
With detailed attention to case law (Member State, ECJ, and ECHR), especially where affecting high-risk areas that have attracted scrutiny, the guidance proceeds systematically through such topics and issues as the following:
- required documentation, policies, and procedures;
- risk assessment tools and analysis frameworks;
- children's data;
- employee and health data;
- international transfers post-Schrems II;
- data subject rights including the right of access;
- data retention and erasure;
- tracking and surveillance; and
- effects of technologies such as artificial intelligence, biometrics, and machine learning.
With its practical examples derived from the author's experience in building GDPR-compliant software, as well as its analysis of case law and enforcement priorities, this incomparable guide enables company data protection officers and compliance staff to advise on key issues with full awareness of the legal and reputational risks and how to mitigate them. It is also sure to be of immeasurable value to concerned regulators and policymakers at all government levels.
Disclaimer: This title is in pre-production and any names, credits or associations are subject to change. The current table of contents and subject matter is for pre-release sample purposes only.
Industry Reviews
Review quotes:
"I purchased this book recently and I'm very glad I did. It's the textbook I have been waiting for. As someone relatively new to data protection, I was finding it very difficult to find books on the practical side of data protection. This book is very clearly laid out with practical examples and case law given for each topic, which is immensely helpful. I would recommend it to any data protection practitioners."
Jennifer Breslin, LLM CIPP/E, AIPP Member
"...it's going to be the go to resource for practitioners"
Tom Gilligan, Data Protection Consultant
"This is very practical guide to implementing the GDPR, written in problem-solving style that provides step-by-step project management approach to building a GDPR-compliant data protection framework. The content of the book is combined with the practical modules in the application and covers the main topics of the GPDR that are necessary to achieve compliance with the GDPR. It is written in plain language understandable to data controllers and processors even with basic knowledge on personal data protection while keeping a high level of professional expertise with a lot of practical examples deriving from the author's experience. That's why could be very useful also to SMEs."
Anamarija Mladinic, Senior Adviser Specialist at Croatian Data Protection Authority, EU ARC Project Manager (LinkedIn)