<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Protection Archives - L2 Cyber Security Solutions Ltd.</title>
	<atom:link href="https://www.l2cybersecurity.com/tag/data-protection/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.l2cybersecurity.com/tag/data-protection/</link>
	<description>#SecuritySimplified</description>
	<lastBuildDate>Thu, 01 Aug 2024 14:54:35 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.l2cybersecurity.com/wp-content/uploads/2023/03/cropped-Logo-Only-Favicon-Transparent-32x32.png</url>
	<title>Data Protection Archives - L2 Cyber Security Solutions Ltd.</title>
	<link>https://www.l2cybersecurity.com/tag/data-protection/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>#WeekendWisdom 085 Vaccination Status Data Protection Concerns</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-085-vaccination-status-data-protection-concerns/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 02 Jul 2021 01:15:24 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Protection Concerns]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Tipperary]]></category>
		<category><![CDATA[Vaccination Status]]></category>
		<category><![CDATA[Vaccination Status Data Protection Concerns]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2558</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 85. This week we&#8217;re going to talk about vaccination status data protection concerns. What is so important about somebody&#8217;s vaccination status? As the vaccination program continues to roll out across the country for the COVID-19 virus, people are getting vaccines on a wide scale. Now I just want to make sure&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-085-vaccination-status-data-protection-concerns/">#WeekendWisdom 085 Vaccination Status Data Protection Concerns</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 85. This week we&#8217;re going to talk about vaccination status data protection concerns.<span id="more-2558"></span></p>
<div style="width: 1920px;" class="wp-video"><video class="wp-video-shortcode" id="video-2558-1" width="1920" height="1080" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-085-lo.mp4?_=1" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-085-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-085-lo.mp4</a></video></div>
<h3>What is so important about somebody&#8217;s vaccination status?</h3>
<p>As the vaccination program continues to roll out across the country for the COVID-19 virus, people are getting vaccines on a wide scale.</p>
<p>Now I just want to make sure that everybody is aware that somebody&#8217;s vaccination status is actually medical information and as such is classified as a special category data and so it needs to be protected.</p>
<h3>Who has Vaccination Status Data Protection Concerns?</h3>
<p>The Data Protection Commission issued some guidance recently, which is <a href="https://www.dataprotection.ie/sites/default/files/uploads/2021-06/Processing%20COVID-19%20Vaccination%20Data%20in%20the%20context%20of%20Employment_0.pdf" target="_blank" rel="noopener">available here</a>. In that they reiterated that except in very limited circumstances, employers are not allowed to ask employees or capture or store information relating to their employees&#8217; vaccination status.</p>
<h3>Why is that the case?</h3>
<p>That is because there is no current public health advice stating that there is a good purpose for doing so. This is the crucial thing, that it has to be public health advice that has to give a good reason otherwise there is no actually legal basis for capturing and storing somebody&#8217;s vaccination status.</p>
<h3>Is there a wider concern here?</h3>
<p>That guidance was applicable to employers and employees but as the country opens up and there is all this talk about people showing their vaccination status to get into pubs and restaurants and things like that. I think that there will continue to be this limitation. Unless public health authorities come out and say otherwise, pubs, restaurants, hotels, anywhere that people can gather, I don&#8217;t believe that capturing somebody&#8217;s vaccination status will be permitted.</p>
<p>So watch out for any updates from public health authorities only and not from the likes of the restaurants association, the vintners, hotels federation, etc.</p>
<p>So that’s it for this week. Lets be careful out there and we’ll talk to you again next week.</p>
<div class="fl-post-content clearfix">
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>L2 Cyber Security are also a partner of <a href="https://www.cyberriskaware.com/" target="_blank" rel="noopener noreferrer">CyberRiskAware</a> for online self-directed Cyber Security Awareness training and Phishing testing.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://twitter.com/L2actual" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2actual/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
</div>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-085-vaccination-status-data-protection-concerns/">#WeekendWisdom 085 Vaccination Status Data Protection Concerns</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-085-lo.mp4" length="38686439" type="video/mp4" />

			</item>
		<item>
		<title>#WeekendWisdom 028 Data Protection as Lockdown is eased.</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-028-data-protection-as-lockdown-is-eased/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 15 May 2020 08:30:03 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Health Screening]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Lockdown]]></category>
		<category><![CDATA[Lockdown Eased]]></category>
		<category><![CDATA[Secure Website forms]]></category>
		<category><![CDATA[Tipperary]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1994</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 28. This week we&#8217;re going to talk about Data Protection as Lockdown is Eased. What data protection issues do we need to consider as lockdown is eased? Next Monday the 18th of May, Ireland begins the first of 5 phases of the easing of lockdown restrictions. Some companies have been advised&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-028-data-protection-as-lockdown-is-eased/">#WeekendWisdom 028 Data Protection as Lockdown is eased.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 28. This week we&#8217;re going to talk about Data Protection as Lockdown is Eased.<span id="more-1994"></span></p>
<div style="width: 1280px;" class="wp-video"><video class="wp-video-shortcode" id="video-1994-2" width="1280" height="720" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2020/05/WeekendWisdom-028-lo.mp4?_=2" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2020/05/WeekendWisdom-028-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2020/05/WeekendWisdom-028-lo.mp4</a></video></div>
<h3>What data protection issues do we need to consider as lockdown is eased?</h3>
<p>Next Monday the 18th of May, Ireland begins the first of 5 phases of the easing of lockdown restrictions. Some companies have been advised to gather people&#8217;s personal data more so than usual, to facilitate perhaps contact tracing or making appointments to ensure social distancing. So here are a few things to consider about that gathering of additional personal data.</p>
<h3>Staff taking customer contact details</h3>
<p>There&#8217;s been reports that some restaurants may take the names and telephone numbers of every member of a party that attends the restaurant, such that contact tracing may be facilitated. There was a story that has emerged out of the US where a restaurant worker has made unwelcome advances towards a female customer, by calling her on her mobile number. So be careful about what staff have access to that data.</p>
<h3>Secure website booking forms</h3>
<p>Also I&#8217;ve become aware of riding schools are opening up as they are outside activities. Some of them are taking bookings online, on their websites. You need to make sure that those websites are secure. That there is a certificate on the site. That there is a padlock. So check that.</p>
<h3>Health screening of customers</h3>
<p>Finally there was another establishment that has installed thermal imaging cameras to screen customers walking in the door. Now that is processing sensitive personal data because that temperature data would be considered a special category of data. So there would absolutely have to be a data protection impact assessment carried out on that setup. Watch out for any kind of health screening you might plan to do.</p>
<p>So that&#8217;s it for this week. Let&#8217;s be careful out there and we&#8217;ll talk to you again next week.</p>
<h3>Follow us on Social media:</h3>
<p>Liam is available on <a href="https://twitter.com/L2_Evangelist" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2_evangelist/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.L2CyberSecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-028-data-protection-as-lockdown-is-eased/">#WeekendWisdom 028 Data Protection as Lockdown is eased.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2020/05/WeekendWisdom-028-lo.mp4" length="24961692" type="video/mp4" />

			</item>
		<item>
		<title>A la carte Data Protection Training</title>
		<link>https://www.l2cybersecurity.com/a-la-carte-data-protection-training/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Mon, 30 Mar 2020 22:54:36 +0000</pubDate>
				<category><![CDATA[Services]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Protection Awareness]]></category>
		<category><![CDATA[Data Protection Awareness Training]]></category>
		<category><![CDATA[Data Protection Training]]></category>
		<category><![CDATA[Staff Data Protection Awareness]]></category>
		<category><![CDATA[Staff Data Protection Awareness Training]]></category>
		<category><![CDATA[Staff Data Protection Training]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2111</guid>

					<description><![CDATA[<p>À la carte Data Protection Training Download these details Make an enquiry L2 Cyber Security Solutions is delighted to be able to offer the following À la carte Data Protection Training, in an online and in-person format. Title: À la carte Data Protection Training. Learning objective: The purpose of this programme is to equip the learner&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/a-la-carte-data-protection-training/">A la carte Data Protection Training</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="fl-builder-content fl-builder-content-2111 fl-builder-content-primary fl-builder-global-templates-locked" data-post-id="2111"><div class="fl-row fl-row-fixed-width fl-row-bg-none fl-node-5ebc52ba7285c fl-row-default-height fl-row-align-center" data-node="5ebc52ba7285c">
	<div class="fl-row-content-wrap">
		<div class="uabb-row-separator uabb-top-row-separator" >
</div>
						<div class="fl-row-content fl-row-fixed-width fl-node-content">
		
<div class="fl-col-group fl-node-5ebc52eb93239" data-node="5ebc52eb93239">
			<div class="fl-col fl-node-5ebc52eb933e1 fl-col-bg-color fl-col-small" data-node="5ebc52eb933e1">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-heading fl-node-5ebc52feed684" data-node="5ebc52feed684">
	<div class="fl-module-content fl-node-content">
		<h1 class="fl-heading">
		<span class="fl-heading-text">À la carte Data Protection Training</span>
	</h1>
	</div>
</div>
</div>
</div>
			<div class="fl-col fl-node-5ebc52eb933ec fl-col-bg-color fl-col-small" data-node="5ebc52eb933ec">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-pp-file-download fl-node-5ebc536edb0b9" data-node="5ebc536edb0b9">
	<div class="fl-module-content fl-node-content">
		<div class="pp-button-wrap pp-button-width-auto pp-button-has-icon">
	<a href="https://www.l2cybersecurity.com/wp-content/uploads/2023/10/A-la-carte-Data-Protection-Training.pdf" target="_self" class="pp-button" role="button" download="A-la-carte-Data-Protection-Training.pdf" aria-label="Download these details">
				<i class="pp-button-icon pp-button-icon-before fi-download"></i>
						<span class="pp-button-text">Download these details</span>
					</a>
</div>
	</div>
</div>
<div class="fl-module fl-module-pp-smart-button fl-node-5eea7c4790fef" data-node="5eea7c4790fef">
	<div class="fl-module-content fl-node-content">
		<div class="pp-button-wrap pp-button-width-auto pp-button-has-icon">
	<a href="mailto:info@l2cybersecurity.com?subject=À%20la%20carte%20Data%20Protection%20Training%20enquiry%20&#038;body=Hi%20there,%0A%0AI%20would%20like%20to%20get%20more%20information%20about%20À%20la%20carte%20data%20protection%20Training,%20please.%0A" target="_blank" class="pp-button" role="button" rel="noopener" aria-label="Make an enquiry">
				<i class="pp-button-icon pp-button-icon-before ua-icon ua-icon-icon-6-mail-envelope-closed2"></i>
						<span class="pp-button-text">Make an enquiry</span>
					</a>
</div>
	</div>
</div>
</div>
</div>
	</div>

<div class="fl-col-group fl-node-5ebc52ba74e29" data-node="5ebc52ba74e29">
			<div class="fl-col fl-node-5ebc52ba7501e fl-col-bg-color" data-node="5ebc52ba7501e">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-rich-text fl-node-5ebc52ba7fe0c" data-node="5ebc52ba7fe0c">
	<div class="fl-module-content fl-node-content">
		<div class="fl-rich-text">
	<p><a href="https://www.l2cybersecurity.com/">L2 Cyber Security Solutions</a> is delighted to be able to offer the following À la carte Data Protection Training, in an online and in-person format.</p>
<h2>Title: À la carte Data Protection Training.</h2>
<h2>Learning objective:</h2>
<p>The purpose of this programme is to equip the learner with the knowledge and skill to identify their organisation’s obligations to protect the personal data of the individuals that they work for and with.</p>
<h2>Our range of topics to choose from include:</h2>
<p><strong>The basics:</strong></p>
<ul>
<li>What is Personal Data and what do we mean by processing</li>
<li>Comprehending the terminology of the GDPR</li>
<li>Do you need a Data Protection Officer (DPO)?</li>
</ul>
<p><strong>The important items:</strong></p>
<ul>
<li>Interpreting the GDPR’s principles</li>
<li>Knowing the rights of the individual</li>
<li>Understanding the appropriate legal basis for processing (incl. consent)</li>
<li>Data Protection by design</li>
<li>How to identify and handle International Transfers</li>
<li>Establish what other documentation is required</li>
</ul>
<p><strong>Documentation and Procedures:</strong></p>
<ul>
<li>Handling Sensitive Personal Data appropriately</li>
<li>Creating a simple Data Inventory</li>
<li>Establishing a Data Protection Policy</li>
<li>What needs to be included in a right-to-be-informed document</li>
<li>Producing procedures to handle an individual’s rights</li>
<li>Knowing the kind of records you need to keep</li>
<li>Understanding Data Processing Agreements</li>
<li>When it hits the fan – using a Data Breach handling procedure</li>
<li>Securing the business with an Information Security Policy</li>
<li>When and How to conduct a Data Protection Impact Assessment</li>
<li>What is a Legitimate Interest Assessment and how should you carry it out</li>
<li>What if it all goes wrong – what can the Data Protection Commission do</li>
</ul>
<h2>Duration:</h2>
<p>Each topic is approximately 20 minutes each, including time for Questions and Answers.</p>
<h2>Audience:</h2>
<p>Staff, contractors or volunteers who have no or limited knowledge of data protection and specifically the GDPR legislation. Also organisations who need to put in place policies, procedures and records keeping for the GDPR in their business.</p>
<h2>Delivery Format:</h2>
<ul>
<li>Online – Presentation, using Google Meet (or your own online platform of choice).</li>
<li>In-person – Interactive workshop over the selected duration.</li>
</ul>
<h2>Also Included:</h2>
<ul>
<li>A link to a softcopy of any slides will be provided during the session.</li>
<li>Link to additional free resources would be included too.</li>
<li>Certificates of attendance if required.</li>
</ul>
<h2>Pricing:</h2>
<ul>
<li>Please see our website for our current prices:</li>
</ul>
<p style="padding-left: 40px;"><a href="https://www.l2cybersecurity.com/prices/">https://www.l2cybersecurity.com/prices/</a></p>
<h2>Contact us:</h2>
<p><a href="mailto:info@L2CyberSecurity.com">info@L2CyberSecurity.com</a></p>
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://ie.linkedin.com/in/l2actual">LinkedIn</a>, <a href="https://infosec.exchange/@L2actual">Mastodon</a> and <a href="https://www.youtube.com/@L2actual/videos">YouTube</a>.</p>
<p>Follow L2 Cyber on <a href="https://www.linkedin.com/company/l2cyber/">LinkedIn</a>.</p>
</div>
	</div>
</div>
</div>
</div>
	</div>
		</div>
	</div>
</div>
</div><div class="uabb-js-breakpoint" style="display: none;"></div><p>The post <a href="https://www.l2cybersecurity.com/a-la-carte-data-protection-training/">A la carte Data Protection Training</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Staff Data Protection Awareness Training</title>
		<link>https://www.l2cybersecurity.com/staff-data-protection-awareness-training/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Mon, 30 Mar 2020 22:52:57 +0000</pubDate>
				<category><![CDATA[Services]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Protection Awareness]]></category>
		<category><![CDATA[Data Protection Awareness Training]]></category>
		<category><![CDATA[Staff Data Protection Awareness]]></category>
		<category><![CDATA[Staff Data Protection Awareness Training]]></category>
		<category><![CDATA[Staff Data Protection Training]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2112</guid>

					<description><![CDATA[<p>Staff Data Protection Awareness Training Download these details Make an enquiry L2 Cyber Security Solutions is delighted to be able to offer the following Staff Data Protection Training, in an online and in-person format. Title: Data Protection Awareness Training for staff. Learning objective: The purpose of this programme is to equip the learner with the knowledge&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/staff-data-protection-awareness-training/">Staff Data Protection Awareness Training</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="fl-builder-content fl-builder-content-2112 fl-builder-content-primary fl-builder-global-templates-locked" data-post-id="2112"><div class="fl-row fl-row-fixed-width fl-row-bg-none fl-node-5ebc52ba7285c fl-row-default-height fl-row-align-center" data-node="5ebc52ba7285c">
	<div class="fl-row-content-wrap">
		<div class="uabb-row-separator uabb-top-row-separator" >
</div>
						<div class="fl-row-content fl-row-fixed-width fl-node-content">
		
<div class="fl-col-group fl-node-5ebc52eb93239" data-node="5ebc52eb93239">
			<div class="fl-col fl-node-5ebc52eb933e1 fl-col-bg-color fl-col-small" data-node="5ebc52eb933e1">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-heading fl-node-5ebc52feed684" data-node="5ebc52feed684">
	<div class="fl-module-content fl-node-content">
		<h1 class="fl-heading">
		<span class="fl-heading-text">Staff Data Protection Awareness Training</span>
	</h1>
	</div>
</div>
</div>
</div>
			<div class="fl-col fl-node-5ebc52eb933ec fl-col-bg-color fl-col-small" data-node="5ebc52eb933ec">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-pp-file-download fl-node-5ebc536edb0b9" data-node="5ebc536edb0b9">
	<div class="fl-module-content fl-node-content">
		<div class="pp-button-wrap pp-button-width-auto pp-button-has-icon">
	<a href="https://www.l2cybersecurity.com/wp-content/uploads/2023/10/Staff-Data-Protection-Awareness-Training.pdf" target="_self" class="pp-button" role="button" download="Staff-Data-Protection-Awareness-Training.pdf" aria-label="Download these details">
				<i class="pp-button-icon pp-button-icon-before fi-download"></i>
						<span class="pp-button-text">Download these details</span>
					</a>
</div>
	</div>
</div>
<div class="fl-module fl-module-pp-smart-button fl-node-5eea7c4790fef" data-node="5eea7c4790fef">
	<div class="fl-module-content fl-node-content">
		<div class="pp-button-wrap pp-button-width-auto pp-button-has-icon">
	<a href="mailto:info@l2cybersecurity.com?subject=Staff%20Data%20Protection%20awareness%20training%20enquiry%20&#038;body=Hi%20there,%0A%0AI%20would%20like%20to%20get%20more%20information%20about%20staff%20data%20protection%20awarenesss%20training,%20please.%0A" target="_blank" class="pp-button" role="button" rel="noopener" aria-label="Make an enquiry">
				<i class="pp-button-icon pp-button-icon-before ua-icon ua-icon-icon-6-mail-envelope-closed2"></i>
						<span class="pp-button-text">Make an enquiry</span>
					</a>
</div>
	</div>
</div>
</div>
</div>
	</div>

<div class="fl-col-group fl-node-5ebc52ba74e29" data-node="5ebc52ba74e29">
			<div class="fl-col fl-node-5ebc52ba7501e fl-col-bg-color" data-node="5ebc52ba7501e">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-rich-text fl-node-5ebc52ba7fe0c" data-node="5ebc52ba7fe0c">
	<div class="fl-module-content fl-node-content">
		<div class="fl-rich-text">
	<p><a href="https://www.l2cybersecurity.com/">L2 Cyber Security Solutions</a> is delighted to be able to offer the following Staff Data Protection Training, in an online and in-person format.</p>
<h2>Title: Data Protection Awareness Training for staff.</h2>
<h2>Learning objective:</h2>
<p>The purpose of this programme is to equip the learner with the knowledge and skill to identify their organisation’s obligations to protect the personal data of the individuals that they work for and with.</p>
<h2>Content of the Staff Data Protection Awareness Training:</h2>
<p>There are three separate modules in this training.</p>
<h3>1.   Module 1 – The basics</h3>
<ul>
<li>What is Personal Data and what do we mean by processing</li>
<li>Comprehending the terminology of the GDPR</li>
<li>Interpreting the GDPR’s principles</li>
</ul>
<h3>2.   Module 2 – The important stuff</h3>
<ul>
<li>Knowing the rights of the individual</li>
<li>Understanding the appropriate legal basis for processing (incl. consent)</li>
<li>Data Protection by design</li>
</ul>
<h3>3.   Module 3 – What do you need to put in place</h3>
<ul>
<li>Creating a simple Data Inventory</li>
<li>Establish what other documentation is required</li>
<li>What if it all goes wrong – what can the Data Protection Commission do</li>
</ul>
<h2>Duration:</h2>
<p>Each module is 60 minutes, including ample time for Questions and Answers.</p>
<h2>Audience:</h2>
<p>Staff, contractors or volunteers who have no or limited knowledge of data protection and specifically the GDPR legislation.</p>
<h2>Delivery Format:</h2>
<ul>
<li>Online – Presentation, using Google Meet (or your own online platform of choice).</li>
<li>In-person – Interactive workshop over the selected duration.</li>
</ul>
<h2>Also Included:</h2>
<ul>
<li>A link to a softcopy of any slides will be provided during the session.</li>
<li>Link to additional free resources would be included too.</li>
<li>Certificates of attendance if required.</li>
</ul>
<h2>Pricing:</h2>
<ul>
<li>Please see our website for our current prices:</li>
</ul>
<p style="padding-left: 40px;"><a href="https://www.l2cybersecurity.com/prices/">https://www.l2cybersecurity.com/prices/</a></p>
<h2>Contact us:</h2>
<p><a href="mailto:info@L2CyberSecurity.com">info@L2CyberSecurity.com</a></p>
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://ie.linkedin.com/in/l2actual">LinkedIn</a>, <a href="https://infosec.exchange/@L2actual">Mastodon</a> and <a href="https://www.youtube.com/@L2actual/videos">YouTube</a>.</p>
<p>Follow L2 Cyber on <a href="https://www.linkedin.com/company/l2cyber/">LinkedIn</a>.</p>
</div>
	</div>
</div>
</div>
</div>
	</div>
		</div>
	</div>
</div>
</div><div class="uabb-js-breakpoint" style="display: none;"></div><p>The post <a href="https://www.l2cybersecurity.com/staff-data-protection-awareness-training/">Staff Data Protection Awareness Training</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Board Management Data Protection Briefing</title>
		<link>https://www.l2cybersecurity.com/board-management-data-protection-briefing/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Mon, 30 Mar 2020 22:50:22 +0000</pubDate>
				<category><![CDATA[Services]]></category>
		<category><![CDATA[Board Data Protection]]></category>
		<category><![CDATA[Board Data Protection Briefing]]></category>
		<category><![CDATA[Board Management Data Protection Briefing]]></category>
		<category><![CDATA[Board of Directors]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Protection Briefing]]></category>
		<category><![CDATA[Management Data Protection]]></category>
		<category><![CDATA[Management Data Protection Briefing]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2110</guid>

					<description><![CDATA[<p>Board/Management Data Protection Briefing Download these details Make an enquiry L2 Cyber Security Solutions is delighted to be able to offer the following Board/Management Briefing, in an online and in-person format. Title: Data Protection Briefing for Boards or Management. Learning objective: The purpose of this programme is to equip the members of the board/management with the&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/board-management-data-protection-briefing/">Board Management Data Protection Briefing</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="fl-builder-content fl-builder-content-2110 fl-builder-content-primary fl-builder-global-templates-locked" data-post-id="2110"><div class="fl-row fl-row-fixed-width fl-row-bg-none fl-node-5ebc52ba7285c fl-row-default-height fl-row-align-center" data-node="5ebc52ba7285c">
	<div class="fl-row-content-wrap">
		<div class="uabb-row-separator uabb-top-row-separator" >
</div>
						<div class="fl-row-content fl-row-fixed-width fl-node-content">
		
<div class="fl-col-group fl-node-5ebc52eb93239" data-node="5ebc52eb93239">
			<div class="fl-col fl-node-5ebc52eb933e1 fl-col-bg-color fl-col-small" data-node="5ebc52eb933e1">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-heading fl-node-5ebc52feed684" data-node="5ebc52feed684">
	<div class="fl-module-content fl-node-content">
		<h1 class="fl-heading">
		<span class="fl-heading-text">Board/Management Data Protection Briefing</span>
	</h1>
	</div>
</div>
</div>
</div>
			<div class="fl-col fl-node-5ebc52eb933ec fl-col-bg-color fl-col-small" data-node="5ebc52eb933ec">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-pp-file-download fl-node-5ebc536edb0b9" data-node="5ebc536edb0b9">
	<div class="fl-module-content fl-node-content">
		<div class="pp-button-wrap pp-button-width-auto pp-button-has-icon">
	<a href="https://www.l2cybersecurity.com/wp-content/uploads/2023/10/Board-Management-Data-Protection-Briefing.pdf" target="_self" class="pp-button" role="button" download="Board-Management-Data-Protection-Briefing.pdf" aria-label="Download these details">
				<i class="pp-button-icon pp-button-icon-before fi-download"></i>
						<span class="pp-button-text">Download these details</span>
					</a>
</div>
	</div>
</div>
<div class="fl-module fl-module-pp-smart-button fl-node-5eea83e6d5e64" data-node="5eea83e6d5e64">
	<div class="fl-module-content fl-node-content">
		<div class="pp-button-wrap pp-button-width-auto pp-button-has-icon">
	<a href="mailto:info@l2cybersecurity.com?subject=Board/Management%20Data%20Protection%20Briefing%20enquiry%20&#038;body=Hi%20there,%0A%0AI%20would%20like%20to%20get%20more%20information%20about%20the%20Board/Management%20Data%20Protection%20Briefing,%20please.%0A" target="_blank" class="pp-button" role="button" rel="noopener" aria-label="Make an enquiry">
				<i class="pp-button-icon pp-button-icon-before ua-icon ua-icon-icon-6-mail-envelope-closed2"></i>
						<span class="pp-button-text">Make an enquiry</span>
					</a>
</div>
	</div>
</div>
</div>
</div>
	</div>

<div class="fl-col-group fl-node-5ebc52ba74e29" data-node="5ebc52ba74e29">
			<div class="fl-col fl-node-5ebc52ba7501e fl-col-bg-color" data-node="5ebc52ba7501e">
	<div class="fl-col-content fl-node-content"><div class="fl-module fl-module-rich-text fl-node-5ebc52ba7fe0c" data-node="5ebc52ba7fe0c">
	<div class="fl-module-content fl-node-content">
		<div class="fl-rich-text">
	<p><a href="https://www.l2cybersecurity.com/">L2 Cyber Security Solutions</a> is delighted to be able to offer the following Board/Management Briefing, in an online and in-person format.</p>
<h2>Title: Data Protection Briefing for Boards or Management.</h2>
<h2>Learning objective:</h2>
<p>The purpose of this programme is to equip the members of the board/management with the knowledge of their obligations for data protection, under the GDPR and have a strategy for addressing these in their organisation.</p>
<h2>Content of the Board/Management Briefing:</h2>
<ul>
<li>Overview of case studies since GDPR came into force in Ireland</li>
<li>Quick question – do you need a Data Protection Officer (DPO)?</li>
<li>An introduction of the organisation’s obligations</li>
<li>Outline an implementation strategy for the organisation</li>
</ul>
<h2>Duration:</h2>
<p>The briefing will take 45 minutes. There will be plenty of time for Questions and Answers.</p>
<h2>Audience:</h2>
<p>Board members or Senior Management of organisations that want to start the journey of implementing a data protection compliance regime.</p>
<h2>Delivery Format:</h2>
<ul>
<li>Online – Presentation, using Google Meet (or your own online platform of choice).</li>
<li>In-person – Interactive workshop over the selected duration.</li>
</ul>
<h2>Also Included:</h2>
<ul>
<li>A link to a softcopy of any slides will be provided during the session.</li>
<li>Link to additional free resources would be included too.</li>
<li>Certificates of attendance if required.</li>
</ul>
<h2>Pricing:</h2>
<ul>
<li>Please see our website for our current prices:</li>
</ul>
<p style="padding-left: 40px;"><a href="https://www.l2cybersecurity.com/prices/">https://www.l2cybersecurity.com/prices/</a></p>
<h2>Contact us:</h2>
<p><a href="mailto:info@L2CyberSecurity.com">info@L2CyberSecurity.com</a></p>
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://ie.linkedin.com/in/l2actual">LinkedIn</a>, <a href="https://infosec.exchange/@L2actual">Mastodon</a> and <a href="https://www.youtube.com/@L2actual/videos">YouTube</a>.</p>
<p>Follow L2 Cyber on <a href="https://www.linkedin.com/company/l2cyber/">LinkedIn</a>.</p>
</div>
	</div>
</div>
</div>
</div>
	</div>
		</div>
	</div>
</div>
</div><div class="uabb-js-breakpoint" style="display: none;"></div><p>The post <a href="https://www.l2cybersecurity.com/board-management-data-protection-briefing/">Board Management Data Protection Briefing</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>#WeekendWisdom 020 Working from Home and Data Protection</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-020-working-from-home-and-data-protection/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 20 Mar 2020 11:57:02 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Coronavirus]]></category>
		<category><![CDATA[Covid-19]]></category>
		<category><![CDATA[Covid19]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Pandemic]]></category>
		<category><![CDATA[Tipperary]]></category>
		<category><![CDATA[Working from Home]]></category>
		<category><![CDATA[Working from Home and Data Protection]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1887</guid>

					<description><![CDATA[<p>welcome to #WeekendWisdom number 20. This week we&#8217;re going to talk about working from home and data protection. Yep! I&#8217;m Working from Home for the first time. Now that the #COVID19 pandemic has truly gripped the planet, lots of employers are asking their employees to work from home. If you&#8217;re in the situation for the&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-020-working-from-home-and-data-protection/">#WeekendWisdom 020 Working from Home and Data Protection</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>welcome to #WeekendWisdom number 20. This week we&#8217;re going to talk about working from home and data protection.<span id="more-1887"></span></p>
<p><div style="width: 1280px;" class="wp-video"><video class="wp-video-shortcode" id="video-1887-3" width="1280" height="720" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2020/03/WeekendWisdom-020-lo.mp4?_=3" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2020/03/WeekendWisdom-020-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2020/03/WeekendWisdom-020-lo.mp4</a></video></div></p>
<h3>Yep! I&#8217;m Working from Home for the first time.</h3>
<p>Now that the #COVID19 pandemic has truly gripped the planet, lots of employers are asking their employees to work from home. If you&#8217;re in the situation for the first time your employer probably has provided you with a laptop or a tablet, or some device to be able to do this work from home.</p>
<p>If they have done this they probably also have given you some kind of secure way of connecting into the company emails and into the company file data storage. Your IT support might also have given you guidance on things you need to do to keep that machine safe and secure while you&#8217;re working from home. So please do follow those guidelines.</p>
<h3>So Working from Home and Data Protection, what do I gotta do?</h3>
<p>But if you&#8217;re working with personal data you really, really want to be very careful about that device and how you use this device in your working from home environment. For example you might have younger people in the house and it can be very tempting to let them play with this device or use this device to access the internet, when you&#8217;re not working with it. You must resist that temptation because that device contains potentially sensitive data. You cannot let the young people get access to that data. It must be kept secure.</p>
<h3>What about paper personal data?</h3>
<p>Similarly if you were printing things at home and particularly if you&#8217;re printing sensitive personal data, so things like health information or religious, political persuasions, that type of information.</p>
<p>Sensitive Personal Data:</p>
<ul>
<li>Race/Ethnic origin</li>
<li>Political Opinions</li>
<li>Religious/Philosophical beliefs</li>
<li>Trade Union Membership</li>
<li>Physical/Mental Health</li>
<li>Sexual Orientation/Sex Life</li>
<li>Genetic data</li>
<li>Biometric data</li>
</ul>
<p>If you&#8217;re going to print that out at home you really need to be able to secure those printouts, those hard copies appropriately and as securely as it would be in the office. So you really shouldn&#8217;t want to be printing that stuff out.</p>
<p>So that’s it for this week. Let’s be careful out there and we’ll talk to you again next week.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">www.L2CyberSecurity.com</a></p>
<p><a href="http://www.twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">www.twitter.com/L2Cyber</a></p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-020-working-from-home-and-data-protection/">#WeekendWisdom 020 Working from Home and Data Protection</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2020/03/WeekendWisdom-020-lo.mp4" length="25218301" type="video/mp4" />

			</item>
		<item>
		<title>First Annual Report from the DPC</title>
		<link>https://www.l2cybersecurity.com/first-annual-report-dpc/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 01 Mar 2019 16:30:03 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Annual Report]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1605</guid>

					<description><![CDATA[<p>The first annual report from the Data Protection Commission, under the auspices of the GDPR has just been released. Have you read it yet? It&#8217;s only 104 pages and unless you are a privacy nerd (like me) you may find it tough going. Truth be told, I struggled to stay fully focused on it as&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/first-annual-report-dpc/">First Annual Report from the DPC</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft size-thumbnail wp-image-1606" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-first-annual-report-150x150.jpg" alt="first annual report" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-first-annual-report-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-first-annual-report.jpg 300w" sizes="(max-width: 150px) 100vw, 150px" />The first annual report from the Data Protection Commission, under the auspices of the GDPR has just been released. <span id="more-1605"></span>Have you read it yet? It&#8217;s only 104 pages and unless you are a privacy nerd (like me) you may find it tough going. Truth be told, I struggled to stay fully focused on it as I read through it.</p>
<h3>Surely this isn&#8217;t the first annual report?</h3>
<p>The office of the Data Protection Commissioner has been around for many many years and have issued many many annual reports. When the GDPR came along on 25th May, the office was renamed to be the Data Protection Commission. This report (which you can <a href="https://www.dataprotection.ie/sites/default/files/uploads/2019-03/DPC Annual Report 25 May - 31 December 2018.pdf" target="_blank" rel="noopener noreferrer">read here</a>) is their first report covering the period 25th May &#8211; 31st December 2018.</p>
<p>Due to the fact that there are investigations still going on from before 25th May 2018, under the previous legislation, the report shows two sets of figures. This post will concentrate on the GDPR figures.</p>
<h3>What are the highlights?</h3>
<p>There were nearly 2,000 complaints made. The top 10 of these accounted for 94% of all complaints. They are:</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-1607" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/Report-complaints.jpg" alt="Top 10 GDPR complaints 2018" width="457" height="603" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/Report-complaints.jpg 457w, https://www.l2cybersecurity.com/wp-content/uploads/2019/03/Report-complaints-227x300.jpg 227w" sizes="(max-width: 457px) 100vw, 457px" /></p>
<p>Issues around access rights was also the number 1 complaint (39%) under the previous legislation, so this is the most important area that a business or organisation should get right. I&#8217;m a little surprised by the complaints under Right of Rectification. That is such a simple one to get correct, why were there 30 complaints? ?‍♂️</p>
<h3>Data breaches are on the rise.</h3>
<p>There were nearly 3,700 data breaches reported. 85% of them were in the category of unauthorised disclosure which wasn&#8217;t really surprising.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-1608" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-Data-Breaches-2018.jpg" alt="Data breaches 2018" width="500" height="432" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-Data-Breaches-2018.jpg 500w, https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-Data-Breaches-2018-300x259.jpg 300w" sizes="(max-width: 500px) 100vw, 500px" /></p>
<p>It&#8217;s interesting to note that there were 226 incidents (6%) which related to paper records. I actually think that figure should be a little bit higher, as I suspect people don&#8217;t consider losing or poorly disposing of paper records to be a proper data breach.</p>
<h3>What about the Facebook problems reported last year?</h3>
<p>They are in there too. There are 15 Statutory Inquiries into multinational technology companies. 10 of these inquiries relate to Facebook (7), or Facebook owned companies (WhatsApp 2 and Instagram 1). Of those 10 complaints 4 related to Legal Basis for processing and 3 relate to the <a href="https://www.l2cybersecurity.com/facebook-breach-dpc-public/" target="_blank" rel="noopener noreferrer">data breach reported in September 2018</a>.</p>
<p>The other companies that had inquiries ongoing are Apple with 2, Twitter 2 and LinkedIn 1.</p>
<h3>Was there anything else interesting in the report?</h3>
<p>Well yes there was. It&#8217;s to do with how the DPC acted when dealing with some of the complaints they came across. There were a few case studies provided (pages 24-26). The DPC handled these without the need to impose sanctions, by making the data controller aware of their failings and providing ways to rectify the situation.</p>
<p>What was also interesting was where complaints had come in about data controllers, who had been investigated previously by the Office of the Data Protection Commissioner. In these cases, the DPC prosecuted them in court and had financial penalties applied (pages 64-67). These cases were taken under previous legislation, so the sanctions were small enough. But this shows that if you, as a controller, come to the DPC&#8217;s attention multiple times, they will take a dim view of your behaviour.</p>
<h3>Conclusion:</h3>
<p>There was a lot more to this first annual report than what I covered above, but for most businesses, these are the items that matter.</p>
<p>If you would like to avail of a free 1 hour consultation to find out what you need to do to prepare your business for the GDPR, then please send an e-mail to <a href="mailto:info@l2cybersecurity.com">info@l2cybersecurity.com</a> and somebody will get back to you.</p>
<p>#GDPR #SimpleGDPR</p>
<p>#SecuritySimplified</p>
<p>The post <a href="https://www.l2cybersecurity.com/first-annual-report-dpc/">First Annual Report from the DPC</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GDPR fines are starting to come.</title>
		<link>https://www.l2cybersecurity.com/gdpr-fines-starting-to-come/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Wed, 28 Nov 2018 12:44:31 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[GDPR fines]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1469</guid>

					<description><![CDATA[<p>Shortly after I posted about the Austrian GDPR fine, another fine was issued by the regulatory authority in Portugal. Late last week the German regulatory authority imposed another fine on an App maker. So the GDPR fines are beginning to come. Let&#8217;s take a quick look at these three cases and then see what you&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/gdpr-fines-starting-to-come/">GDPR fines are starting to come.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-1471" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/11/GDPR-fines-150x150.jpg" alt="GDPR fines" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/11/GDPR-fines-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2018/11/GDPR-fines.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />Shortly after I posted about the <a href="https://www.l2cybersecurity.com/gdpr-hasnt-gone-away/" target="_blank" rel="noopener">Austrian GDPR fine</a>, another fine was issued by the regulatory authority in Portugal. Late last week the German regulatory authority imposed another fine on an App maker. So the GDPR fines are beginning to come. Let&#8217;s take a quick look at these three cases and then see what you can do.<span id="more-1469"></span></p>
<h3></h3>
<h3></h3>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h3>Austrian surveillance cost €4.8K</h3>
<p>Just to recap, a business owner had <a href="https://digital.freshfields.com/post/102f39w/first-gdpr-fine-issued-by-austrian-data-protection-regulator" target="_blank" rel="noopener">CCTV installed</a> outside their premises. One camera was recording a large portion of the public footpath. This was judged to be too invasive and there was poor signage. The regulatory authority hit them with a modest €4,800 fine. The Austrian data protection authority had 36 other proceedings pending at that time.</p>
<h3>Portuguese hospital with too many doctor&#8217;s accounts hit for €400K</h3>
<p>An unnamed hospital in Portugal had 985 doctor&#8217;s accounts on it&#8217;s IT system and only 296 doctors on staff. It seems that non-Doctor types (e.g. psychologists and dietitians) used doctor accounts to access patient data. What is most troubling is that a doctor account has unrestricted access to every single patient&#8217;s data.</p>
<p>You might not think this is a big deal, but you&#8217;re dealing with sensitive personal data here. There should be some controls on access to it, including audit logs of any and all access made by authorised personnel.</p>
<p><a href="https://www.insideprivacy.com/data-privacy/portuguese-hospital-receives-and-contests-400000-e-fine-for-gdpr-infringement/" target="_blank" rel="noopener">The regulator has imposed</a> a €400,000 fine on the hospital, which is appealing the judgement. The Portuguese Government have not yet fully implemented the GDPR, but the regulator is acting as if it was in place.</p>
<h3>App maker who cooperated, still fined €20K</h3>
<p>A German chat platform, knuddles.de had a breach in which <a href="https://www.baden-wuerttemberg.datenschutz.de/lfdi-baden-wuerttemberg-verhaengt-sein-erstes-bussgeld-in-deutschland-nach-der-ds-gvo/" target="_blank" rel="noopener">330,000 e-mail addresses</a> (in German) and their account passwords were stolen by hackers. The passwords were in plain text (no hashing or encrypting was applied). It was the screw-up with the password that caused the fine. They hadn&#8217;t applied appropriate technical or organisational controls to protect the data.</p>
<p>The regulatory authority acknowledged that Knuddles were very proactive in reporting the breach and the subsequent follow up. They have implemented stronger security controls in a very short time. In consultation with the regulator they have more measures coming in due course.</p>
<p>The regulator also looked at the financial  strength of the company in determining the fine, not wanting to place the business under any financial burden. So the fine was proportionate. I would hate to think what might have been the case if they hadn&#8217;t cooperated.</p>
<h3>To avoid GDPR fines, budget now to prepare early in 2019</h3>
<p>If your business hasn&#8217;t put in place any policies or procedures to address the requirements of the GDPR, you should look at addressing this soon. Most annual budgets will have been exhausted by now, so put in place a sensible sum for GDPR preparation work, early next year.</p>
<ul>
<li>If you haven&#8217;t attended a GDPR awareness event, then seek one out or give us a call on <span style="text-decoration: underline;"><span style="color: #0000ff; text-decoration: underline;">087-436-2675</span></span>.</li>
<li>We are now offering <a href="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/GDPR-Practical-Training.pdf" target="_blank" rel="noopener">Practical GDPR Training</a>, which can give you virtually everything you need to be as compliant as possible. Being &#8220;100% GDPR compliant&#8221; is not something that can be stated presently, as there is no certification available to support such a declaration.</li>
<li>Or if you prefer to keep making money for your business and not be distracted, then we can do the work for you. Send us an e-mail to <a href="mailto:info@L2CyberSecurity.com">info@L2CyberSecurity.com</a> and we&#8217;ll get in touch.</li>
</ul>
<p>#GDPR</p>
<p>#SimpleGDPR</p>
<p>#SecuritySimplified</p>
<p>The post <a href="https://www.l2cybersecurity.com/gdpr-fines-starting-to-come/">GDPR fines are starting to come.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NUI Galway Data Breach &#8211; Lessons learned?</title>
		<link>https://www.l2cybersecurity.com/nui-galway-data-breach-lessons-learned/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Wed, 21 Nov 2018 10:16:35 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Best Practice]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[USB]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1451</guid>

					<description><![CDATA[<p>The NUI Galway data breach that was revealed this week is concerning. Particularly the initial reports about the breach, which weren&#8217;t very clear. If you hadn&#8217;t already heard, a USB memory stick was mislaid. This memory stick may have had personal data on 5% of the student population. This 5% of an 18,000 student population&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/nui-galway-data-breach-lessons-learned/">NUI Galway Data Breach &#8211; Lessons learned?</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-1456" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/11/nui-galway-data-breach-150x150.jpg" alt="nui galway data breach" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/11/nui-galway-data-breach-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2018/11/nui-galway-data-breach.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />The NUI Galway data breach that was revealed this week is concerning. Particularly the initial reports about the breach, which weren&#8217;t very clear. <span id="more-1451"></span>If you hadn&#8217;t already heard, a USB memory stick was mislaid. This memory stick <em><strong>may</strong></em> have had personal data on 5% of the student population. This 5% of an 18,000 student population gives us approximately 900 individuals being impacted by this breach. That personal data <em><strong>may</strong></em> have included exam results, as reported <a href="https://www.independent.ie/irish-news/news/university-at-centre-of-potential-data-breach-after-usb-stick-goes-missing-37542617.html" target="_blank" rel="noopener">by the Irish Independent</a>.</p>
<blockquote><p>While the University is unclear on the contents of the portable device, it may have held a file containing names of approximately 5% of the student body, their student number and exam results.</p></blockquote>
<p>It&#8217;s the uncertainty that is most worrying to me. Also their claim that they have strict policies in place relating to portable devices is a bit disingenuous. I&#8217;ve been through <a href="http://www.nuigalway.ie/about-us/office-secretary/policies-procedures/" target="_blank" rel="noopener">the policies</a> and also looked at their <a href="http://www.nuigalway.ie/data-protection/" target="_blank" rel="noopener">data protection section</a> and found some conflicting direction with regard to data handling and USB memory sticks.</p>
<p>The <a href="http://www.nuigalway.ie/media/oifiganrunai/files/QA401-Data-Handling.pdf" target="_blank" rel="noopener">Data Handling Policy</a> states the following about &#8220;NUI Galway Highly Restricted&#8221; data:</p>
<blockquote><p>Storage of this data outside of the source system, for example on a laptop or memory stick; must be approved by the data owner. Where data is held outside the source system it must be encrypted.</p></blockquote>
<p>That seems quite sensible, as approval would mean that somebody would know exactly what data is on there and it would then be encrypted. However their <a href="http://www.nuigalway.ie/media/informationsolutionsservices/files/ictpolicies/QA409_encryption-policy.pdf" target="_blank" rel="noopener">Encryption policy</a>, has something else to say on USB memory sticks:</p>
<blockquote><p>Portable storage capability such as DVD’s, CD’s and USB flash drives should not be utilised for classified data storage or transfer, even in an encrypted format.</p></blockquote>
<p>So the handling policy says it&#8217;s fine, but the encryption policy says no. It&#8217;s obvious that the data handling policy wasn&#8217;t followed with this data breach.</p>
<p>I thought it interesting that they have plenty on their site for how to use USB memory sticks and the <a href="http://www.nuigalway.ie/information-solutions-services/servicesforstaff/pcsuites/usbstorage/" target="_blank" rel="noopener">protections they have in place</a>.</p>
<blockquote><p>ISS have <strong>disabled Autorun</strong> on the all computers in the PC Suites as a precautionary measure to prevent the spread of viruses.  When autorun is disabled, a USB memory stick or software on a CD or DVD will no longer automatically start when inserted.</p></blockquote>
<p>So that&#8217;s great &#8230; lots of protection there &#8230; or maybe not. What if the USB device impersonated a keyboard? It could inject keystrokes that open up a command line, execute a command to download dodgy software and execute it. <a href="https://www.howtogeek.com/203061/don%E2%80%99t-panic-but-all-usb-devices-have-a-massive-security-problem/" target="_blank" rel="noopener">I&#8217;m not making this up</a>. The USB stick could also fry the electronics on your computer. Again <a href="https://www.l2cybersecurity.com/usb-machine-killer/" target="_blank" rel="noopener">this is something that happens</a>.</p>
<p>These USB memory sticks are such a problem from a data breach perspective that I always recommend companies and organisations to either block them completely or put in place a solution that automatically encrypts all data on them.</p>
<p>I did dedicate <a href="https://www.l2cybersecurity.com/ix-never-insert-a-strange-usb-memory-stick/" target="_blank" rel="noopener">an entire commandment</a> to USB memory sticks. So you can get my deeply held views in there.</p>
<p>The NUI Galway data breach was an embarrassment for the University. I don&#8217;t think the exam results could be classified as sensitive personal data (special category). But I&#8217;m sure students wouldn&#8217;t like these been released publicly. As long as the powers that be learn a lesson from this sorry situation and implement more rigorous technical solutions, then it will hopefully prevent future, larger and more sanction-worthy breaches.</p>
<p>Lets be careful out there.</p>
<p>#SecuritySimplified #GDPR #SimpleGDPR</p>
<p>The post <a href="https://www.l2cybersecurity.com/nui-galway-data-breach-lessons-learned/">NUI Galway Data Breach &#8211; Lessons learned?</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Facebook are only fined £500,000</title>
		<link>https://www.l2cybersecurity.com/facebook-are-only-fined-500000/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 26 Oct 2018 10:27:16 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Fined]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[ICO]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1444</guid>

					<description><![CDATA[<p>You remember the Facebook/Cambridge Analytica mess from earlier this year? Well, Facebook have been issued with a notice that they are to be fined £500,000 as a result of this. &#8220;What? Facebook are only fined £500,000?&#8221; I hear you cry. Yes that is maximum penalty that the Information Commissioners Office (ICO) in the UK are able to&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/facebook-are-only-fined-500000/">Facebook are only fined £500,000</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-1445" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/facebook-are-only-fined-150x150.jpeg" alt="Facebook are only fined £500,000" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/facebook-are-only-fined-150x150.jpeg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2018/10/facebook-are-only-fined.jpeg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />You remember the <a href="https://www.l2cybersecurity.com/cambridge-analytica-nosey-ninnies/" target="_blank" rel="noopener">Facebook/Cambridge Analytica mess</a> from earlier this year? Well, Facebook have been issued with a notice that <a href="https://ico.org.uk/media/action-weve-taken/mpns/2260051/r-facebook-mpn-20181024.pdf" target="_blank" rel="noopener">they are to be fined £500,000</a> as a result of this. &#8220;What? Facebook are only fined £500,000?&#8221; I hear you cry. <span id="more-1444"></span>Yes that is maximum penalty that the Information Commissioners Office (ICO) in the UK are able to levy under the Data Protection Act 1998.</p>
<p>&#8220;But where are the €20m or 4% of turnover fines for violating the GDPR?&#8221; you shout. As the underlying data breach incident occurred some years ago and surfaced before the #GDPR went into effect in May 2018, then they couldn&#8217;t be prosecuted under the Data Protection Act 2018, which implements the GDPR.</p>
<p>But this is still a significant judgement. The ICO has gone for the maximum possible penalty against Facebook, showing that what they were up to was completely unacceptable and rightly so. They found that Facebook had breached two of the principles of data protection:</p>
<ol>
<li>Facebook had unfairly processed personal data.</li>
<li>And they didn&#8217;t put in place appropriate measures to prevent unauthorised or unlawful processing of personal data.</li>
</ol>
<p>So while Facebook are only fined £500,000 this time, this is a clear indication that data protection authorities won&#8217;t be afraid of going after the maximum fines available to them for failures in respect to protecting peoples personal data.</p>
<p>Also don&#8217;t forget that the Irish Data Protection Commissioner is <a href="https://www.l2cybersecurity.com/facebook-breach-dpc-public/" target="_blank" rel="noopener">investigating Facebook for a GDPR era incident</a>. That incident started with 50m people affected with another 40m possibly impacted. It dropped down to only ~30m affected &#8230; but that&#8217;s still ~30,000,000 people. Of those, 14m had the following personal data accessed:</p>
<blockquote><p>Username, gender, locale/language, relationship status, religion, hometown, self-reported current city, birthdate, device types used to access Facebook, education, work, the last 10 places they checked into or were tagged in, website, people or Pages they follow, and the 15 most recent searches.</p></blockquote>
<p>That is a massive amount of personal data to have been harvested, and could definitely be used against the victims. That particular investigation will be a big one and will probably run into some time in 2019.</p>
<p>In the meantime, lets be careful out there.</p>
<p>#SecuritySimplified</p>
<p>The post <a href="https://www.l2cybersecurity.com/facebook-are-only-fined-500000/">Facebook are only fined £500,000</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
