{"id":74459,"date":"2018-05-24T17:42:28","date_gmt":"2018-05-24T15:42:28","guid":{"rendered":"https:\/\/www.voyages-d-affaires.com\/?p=74459"},"modified":"2018-05-28T09:44:37","modified_gmt":"2018-05-28T07:44:37","slug":"soulis-oppidum-security-rgpd","status":"publish","type":"post","link":"https:\/\/www.voyages-d-affaires.com\/en\/soulis-oppidum-security-rgpd","title":{"rendered":"Interview with Fabien Soulis: Fabien Soulis, Oppidum Security"},"content":{"rendered":"<h3>What does the new RGPD regulation, which comes into force on 25 May, specify?<\/h3>\n<p><strong>Fabien Soulis -<\/strong> First of all, under the French Data Protection Act (Loi Informatiques et Libert\u00e9s - LIL), personal data is defined as \"any information about an individual or an entity\". <em>any information relating to an identified or identifiable natural person by reference to an identification number or to one or more factors specific to that person<\/em> \". Visit <a href=\"https:\/\/www.voyages-d-affaires.com\/en\/rgpd-donnee-union-europeenne-20180129.html\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>RGPD<\/strong> <\/a>will therefore have a direct impact on the way in which organisations collect, process and store personal data within their information systems. Appropriate technical and organisational measures will therefore need to be put in place to offer the highest possible level of data protection. This is known as the principle of <strong>\"privacy by design<\/strong> which is one of the central concepts of the RGPD.<\/p>\n<h3>What methodology should be adopted to incorporate this \"privacy by design\" principle into information systems in order to make them compliant with the RGPD?<\/h3>\n<p>F. S. - First we need to create a <strong>data processing register<\/strong>which is used to document the activities for which you process personal data. Keeping this register is compulsory, as it facilitates the work of an inspector in the event of an audit of the correct application of the RGPD within your organisation. For each activity, you will describe the nature of the activity (e.g. prospect management), the purpose for which the personal data is processed (e.g. organisation of marketing campaigns), the type of people whose data you collect or use (e.g. customers, newsletter subscribers, etc.), the nature of the personal data collected (e.g. customers, newsletter subscribers, etc.) and the purpose for which it is used (e.g. marketing campaigns).), the nature of the personal data collected (e.g. marital status, family situation, etc.), how long the data is kept (e.g. 1 year), who has access to this data (e.g. sales staff, marketing department, IT department, etc.) and lastly the security measures put in place to protect personal data (antivirus, incident monitoring, etc.). At this stage, if you identify that personal data is being kept for no particular purpose, it should be destroyed. Any processing of personal data should help you to <strong>pursue an identified objective<\/strong> and approved by the people whose personal data you process.<\/p>\n<h3>Once the list of activities has been documented in the register, what is the second step?<\/h3>\n<p><strong>F. S. -<\/strong> It is then necessary to ensure that these activities are accompanied by security measures enabling a high level of data protection to be maintained. To achieve this, the RGPD requires organisations processing personal data to carry out a <strong>\"data privacy impact assessment<\/strong> (DPIA). The aim of this assessment is to identify the risks generated by data processing in order to determine the appropriate means of reducing them. Carrying out a DPIA requires a good <strong>understanding the data lifecycle<\/strong>. To ensure that cyber risks are not overlooked, as they are not always well understood by organisations, it is preferable to call on IT security professionals to assist you.<\/p>\n<blockquote><p>mapping personal data<\/p><\/blockquote>\n<h3>How do you set up this assessment?<\/h3>\n<p><strong>F. S. -<\/strong> The DPIA can be broken down into three stages. To begin with, you need to <strong>mapping personal data<\/strong> throughout their life cycle: input, processing, storage, destruction. At each stage of their life cycle, you need to know where personal data is located in your information systems, and who can access it. You will then need to carry out an analysis in order to<strong>identify risks<\/strong> that could have an impact on the confidentiality of this data. This requires an analysis of both organisational and cyber security risks. Finally, knowing the risks to which personal data is exposed, it is necessary to define the resources to be put in place to guarantee a high level of data protection.<\/p>\n<h3>How do you ensure the confidentiality of personal data?<\/h3>\n<p><strong>F. S. -<\/strong> At the end of each processing register, the legal entity is required to describe the organisational and technical security measures that have been put in place to protect the confidentiality of the data. Data controllers must also describe the control measures they have put in place to protect personal data. The processing register proposed by the CNIL covers six main categories of control:<\/p>\n<ul>\n<li>User access control (examples of possible controls: Document describing the list of people authorised to consult data and their rights in the systems, Periodic review of access, Two-factor authentication for access to critical data, Periodic change of passwords, Analysis of abnormal connections, etc.).<\/li>\n<li>Traceability measures (examples of possible controls: each consultation and copy of data is recorded, periodic analysis of abnormal access, etc.).<\/li>\n<li>Software protection measures (examples of possible controls: antivirus, security updates and patches, security tests, etc.).<\/li>\n<li>Data back-up (examples of possible controls: back-ups are stored in a secure centre, back-ups are destroyed after 1 year, etc.).<\/li>\n<li>Data encryption (examples of possible controls: encryption of hard disks, files, personal data communications, etc.).<\/li>\n<li>Control of subcontractors (example of a possible control: periodic review of the safety level of subcontractors, etc.).<\/li>\n<\/ul>\n<p>The selection of controls to be implemented must be in line with the risk analysis carried out during the data privacy impact assessment (DPIA). In order to be successful, the compliance of information systems with the RGPD is therefore a major challenge. <strong>multidisciplinary work<\/strong> which must be undertaken in collaboration with the company's various IT teams and an expert in cyber security.<\/p>\n<p>Internet : <a href=\"https:\/\/oppidumsecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">oppidumsecurity.com<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>As the European regulation on the processing of personal data (RGPD) comes into force on 25 May, Fabien Soulis, partner and head of Oppidum Security's technical division, describes the impact of this change on companies' information systems.<\/p>","protected":false},"author":1,"featured_media":74461,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[105,143],"tags":[],"type-darticle":[51],"n_magazine":[],"class_list":["post-74459","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologies","category-interviews","type-darticle-interview","vapo-free"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.9 (Yoast SEO v25.9) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Le RGPD, &quot;un travail pluridisciplinaire&quot; : Fabien Soulis, Oppidum Security<\/title>\n<meta name=\"description\" content=\"Le r\u00e8glement europ\u00e9en sur le traitement des donn\u00e9es personnelles - le fameux RGPD - entre en vigueur le 25 mai. L&#039;occasion pour Fabien Soulis, associ\u00e9 et directeur du p\u00f4le technique d\u2019Oppidum Security, de d\u00e9tailler les implications du nouveau cadre r\u00e9glementaire sur les syst\u00e8mes d\u2019information des entreprises.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.voyages-d-affaires.com\/en\/soulis-oppidum-security-rgpd\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Interview : Fabien Soulis, Oppidum Security\" \/>\n<meta property=\"og:description\" content=\"Le r\u00e8glement europ\u00e9en sur le traitement des donn\u00e9es personnelles - le fameux RGPD - entre en vigueur le 25 mai. L&#039;occasion pour Fabien Soulis, associ\u00e9 et directeur du p\u00f4le technique d\u2019Oppidum Security, de d\u00e9tailler les implications du nouveau cadre r\u00e9glementaire sur les syst\u00e8mes d\u2019information des entreprises.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.voyages-d-affaires.com\/en\/soulis-oppidum-security-rgpd\" \/>\n<meta property=\"og:site_name\" content=\"Voyages d&#039;affaires\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-24T15:42:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-05-28T07:44:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"700\" \/>\n\t<meta property=\"og:image:height\" content=\"538\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"La R\u00e9daction\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"La R\u00e9daction\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd\",\"url\":\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd\",\"name\":\"Le RGPD, \\\"un travail pluridisciplinaire\\\" : Fabien Soulis, Oppidum Security\",\"isPartOf\":{\"@id\":\"https:\/\/www.voyages-d-affaires.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg\",\"datePublished\":\"2018-05-24T15:42:28+00:00\",\"dateModified\":\"2018-05-28T07:44:37+00:00\",\"author\":{\"@id\":\"https:\/\/www.voyages-d-affaires.com\/#\/schema\/person\/8425ec1d37ab5f25f03c8e8897b93615\"},\"description\":\"Le r\u00e8glement europ\u00e9en sur le traitement des donn\u00e9es personnelles - le fameux RGPD - entre en vigueur le 25 mai. L'occasion pour Fabien Soulis, associ\u00e9 et directeur du p\u00f4le technique d\u2019Oppidum Security, de d\u00e9tailler les implications du nouveau cadre r\u00e9glementaire sur les syst\u00e8mes d\u2019information des entreprises.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#primaryimage\",\"url\":\"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg\",\"contentUrl\":\"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg\",\"width\":700,\"height\":538,\"caption\":\"Fabien Soulis, associ\u00e9 et directeur du p\u00f4le technique d\u2019Oppidum Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.voyages-d-affaires.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Interview : Fabien Soulis, Oppidum Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.voyages-d-affaires.com\/#website\",\"url\":\"https:\/\/www.voyages-d-affaires.com\/\",\"name\":\"Voyages d&#039;affaires\",\"description\":\"media fran\u00e7ais du Voyage d&#039;Affaires &amp; du MICE\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.voyages-d-affaires.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.voyages-d-affaires.com\/#\/schema\/person\/8425ec1d37ab5f25f03c8e8897b93615\",\"name\":\"La R\u00e9daction\",\"url\":\"https:\/\/www.voyages-d-affaires.com\/en\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The RGPD, \"a multidisciplinary task\": Fabien Soulis, Oppidum Security","description":"The European regulation on the processing of personal data - the so-called RGPD - comes into force on 25 May. Fabien Soulis, Partner and Director of Oppidum Security's Technical Division, takes this opportunity to explain the implications of the new regulatory framework for corporate information systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.voyages-d-affaires.com\/en\/soulis-oppidum-security-rgpd","og_locale":"en_GB","og_type":"article","og_title":"Interview : Fabien Soulis, Oppidum Security","og_description":"Le r\u00e8glement europ\u00e9en sur le traitement des donn\u00e9es personnelles - le fameux RGPD - entre en vigueur le 25 mai. L'occasion pour Fabien Soulis, associ\u00e9 et directeur du p\u00f4le technique d\u2019Oppidum Security, de d\u00e9tailler les implications du nouveau cadre r\u00e9glementaire sur les syst\u00e8mes d\u2019information des entreprises.","og_url":"https:\/\/www.voyages-d-affaires.com\/en\/soulis-oppidum-security-rgpd","og_site_name":"Voyages d&#039;affaires","article_published_time":"2018-05-24T15:42:28+00:00","article_modified_time":"2018-05-28T07:44:37+00:00","og_image":[{"width":700,"height":538,"url":"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg","type":"image\/jpeg"}],"author":"La R\u00e9daction","twitter_card":"summary_large_image","twitter_misc":{"Written by":"La R\u00e9daction","Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd","url":"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd","name":"The RGPD, \"a multidisciplinary task\": Fabien Soulis, Oppidum Security","isPartOf":{"@id":"https:\/\/www.voyages-d-affaires.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#primaryimage"},"image":{"@id":"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#primaryimage"},"thumbnailUrl":"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg","datePublished":"2018-05-24T15:42:28+00:00","dateModified":"2018-05-28T07:44:37+00:00","author":{"@id":"https:\/\/www.voyages-d-affaires.com\/#\/schema\/person\/8425ec1d37ab5f25f03c8e8897b93615"},"description":"The European regulation on the processing of personal data - the so-called RGPD - comes into force on 25 May. Fabien Soulis, Partner and Director of Oppidum Security's Technical Division, takes this opportunity to explain the implications of the new regulatory framework for corporate information systems.","breadcrumb":{"@id":"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#primaryimage","url":"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg","contentUrl":"https:\/\/www.voyages-d-affaires.com\/wp-content\/uploads\/2018\/05\/fabien-soulis.jpg","width":700,"height":538,"caption":"Fabien Soulis, associ\u00e9 et directeur du p\u00f4le technique d\u2019Oppidum Security"},{"@type":"BreadcrumbList","@id":"https:\/\/www.voyages-d-affaires.com\/soulis-oppidum-security-rgpd#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.voyages-d-affaires.com\/"},{"@type":"ListItem","position":2,"name":"Interview : Fabien Soulis, Oppidum Security"}]},{"@type":"WebSite","@id":"https:\/\/www.voyages-d-affaires.com\/#website","url":"https:\/\/www.voyages-d-affaires.com\/","name":"Business travel","description":"THE FRENCH BUSINESS TRAVEL &amp; MICE MEDIA","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.voyages-d-affaires.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.voyages-d-affaires.com\/#\/schema\/person\/8425ec1d37ab5f25f03c8e8897b93615","name":"The Editor","url":"https:\/\/www.voyages-d-affaires.com\/en\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/posts\/74459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/comments?post=74459"}],"version-history":[{"count":3,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/posts\/74459\/revisions"}],"predecessor-version":[{"id":74505,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/posts\/74459\/revisions\/74505"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/media\/74461"}],"wp:attachment":[{"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/media?parent=74459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/categories?post=74459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/tags?post=74459"},{"taxonomy":"type-darticle","embeddable":true,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/type-darticle?post=74459"},{"taxonomy":"n_magazine","embeddable":true,"href":"https:\/\/www.voyages-d-affaires.com\/en\/wp-json\/wp\/v2\/n_magazine?post=74459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}