Why Read This Report
Few issues keep higher education executives awake at night more than data privacy. As the new European data protection law, the General Data Protection Regulation (GDPR), comes into effect on May 25, 2018, higher education institutions must position themselves to mitigate risk and strengthen compliance efforts. This comprehensive and complex law covers all processing of personal data, not just data that could be considered private. With this report, The Tambellini Group addresses what higher education needs to understand about GDPR, including how it impacts higher education, and what steps need to be taken to be in compliance. In the fast-changing world of cybersecurity and information governance, this report will prepare institutions for this new era in data protection.
Key Questions Answered
- How will GDPR likely affect U.S. higher education institutions in relation to student, employment and research data?
- How does the scope of GDPR go beyond that of similar U.S. statutes such as the Family Educational Rights and Privacy Act (FERPA) or the Protection of Pupil Rights Amendment (PPRA)?
- What are the fines associated with breaches of the GDPR?
- What preparations should be taken to be compliance-ready by the time GDPR comes into effect?
Report Features
- Download complimentary Executive Summary.
- Author: Ann Kristin Glenster is an acknowledged global legal authority specializing in data privacy. She is deeply involved with the GDPR’s implications, and acts as a private consultant on issues related to GDPR and data protection.
- Co-Author: Katelyn Ilkani, VP, Cybersecurity Advisory Practice, The Tambellini Group.
- Peer Reviewers: Chad Tracy, Director of Information Security, Colby College and David Sherry, CISO, Princeton University.
- Report Length: 57 pages.
- Report Availability: August 2017.
Table of Contents
- Acknowledgements
- Terms of Use
- Disclaimer
- Executive Summary
- Introduction
- GDPR as Part of the EU ‘Constitution’
- Uncertainty Regarding Interpretation and Enforcement
- Applicability to U.S. Higher Education Institutions
- Territorial Reach and Cross-Border Transfer of Data
- Offer of Goods and Services, Monitoring of Behavior
- Representative in the EU
- Cross-border Transfer of Personal Data
- EU-U.S. Privacy Shield Mechanism
- General GDPR Issues
- Processing
- Personal Data
- Special Category Data
- Legal Grounds for Processing
- Data Processing Principles
- Issues of Academic Research
- Consent
- Safeguards and Pseudonymization
- Specific GDPR Issues
- Specific Rights of the Individual
- Transparency and Notices
- Accountability and Risk Evaluation
- Practical Matters
- Data Protection Officer (DPO)
- Main Establishment
- Certificates and Codes of Conduct
- Documentation
- Security
- Breach Notification
- Complaints, Compensation, and Penalties
- Administrative Fines
- Compliance Checklist
- Conclusion
- Bibliography
- Appendixes
- Overview of the GDPR Articles
- Overview of Supervisory Authorities
- Short PowerPoint Summary
- About the Authors
- About The Tambellini Group
- Other Available Reports