Quantify the value of Netskope One SSE – Get the 2024 Forrester Total Economic Impact™ study

cerrar
cerrar
  • Por qué Netskope chevron

    Cambiar la forma en que las redes y la seguridad trabajan juntas.

  • Nuestros clientes chevron

    Netskope atiende a más de 3.400 clientes en todo el mundo, incluidos más de 30 de las 100 empresas más importantes de Fortune

  • Nuestros Partners chevron

    Nos asociamos con líderes en seguridad para ayudarlo a asegurar su viaje a la nube.

Líder en SSE. Ahora es líder en SASE de un solo proveedor.

Descubre por qué Netskope debutó como Líder en el Cuadrante Mágico de Gartner® 2024 para Secure Access Service Edge (SASE) de Proveedor Único.

Obtenga el informe
Testimonios de Clientes

Lea cómo los clientes innovadores navegan con éxito por el cambiante panorama actual de las redes y la seguridad a través de la Plataforma Netskope One.

Obtenga el eBook
Testimonios de Clientes
La estrategia de venta centrada en el partner de Netskope permite a nuestros canales maximizar su expansión y rentabilidad y, al mismo tiempo, transformar la seguridad de su empresa.

Más información sobre los socios de Netskope
Grupo de jóvenes profesionales diversos sonriendo
Tu red del mañana

Planifique su camino hacia una red más rápida, más segura y más resistente diseñada para las aplicaciones y los usuarios a los que da soporte.

Obtenga el whitepaper
Tu red del mañana
Netskope Cloud Exchange

Cloud Exchange (CE) de Netskope ofrece a sus clientes herramientas de integración eficaces para que saquen partido a su inversión en estrategias de seguridad.

Más información sobre Cloud Exchange
Vista aérea de una ciudad
  • Security Service Edge chevron

    Protéjase contra las amenazas avanzadas y en la nube y salvaguarde los datos en todos los vectores.

  • SD-WAN chevron

    Proporcione con confianza un acceso seguro y de alto rendimiento a cada usuario remoto, dispositivo, sitio y nube.

  • Secure Access Service Edge chevron

    Netskope One SASE proporciona una solución SASE nativa en la nube, totalmente convergente y de un único proveedor.

La plataforma del futuro es Netskope

Security Service Edge (SSE), Cloud Access Security Broker (CASB), Cloud Firewall, Next Generation Secure Web Gateway (SWG) y Private Access for ZTNA integrados de forma nativa en una única solución para ayudar a todas las empresas en su viaje hacia la arquitectura Secure Access Service Edge (SASE).

Todos los productos
Vídeo de Netskope
Next Gen SASE Branch es híbrida: conectada, segura y automatizada

Netskope Next Gen SASE Branch converge Context-Aware SASE Fabric, Zero-Trust Hybrid Security y SkopeAI-Powered Cloud Orchestrator en una oferta de nube unificada, marcando el comienzo de una experiencia de sucursal completamente modernizada para la empresa sin fronteras.

Obtenga más información sobre Next Gen SASE Branch
Personas en la oficina de espacios abiertos.
Arquitectura SASE para principiantes

Obtenga un ejemplar gratuito del único manual que necesitará sobre diseño de una arquitectura SASE.

Obtenga el eBook
Libro electrónico de arquitectura SASE para principiantes
Cambie a los servicios de seguridad en la nube líderes del mercado con una latencia mínima y una alta fiabilidad.

Más información sobre NewEdge
Autopista iluminada a través de las curvas de la ladera de la montaña
Habilite de forma segura el uso de aplicaciones de IA generativa con control de acceso a aplicaciones, capacitación de usuarios en tiempo real y la mejor protección de datos de su clase.

Descubra cómo aseguramos el uso generativo de IA
Habilite de forma segura ChatGPT y IA generativa
Soluciones de confianza cero para implementaciones de SSE y SASE

Más información sobre Confianza Cero
Conducción en barco en mar abierto
Netskope logra la alta autorización FedRAMP

Elija Netskope GovCloud para acelerar la transformación de su agencia.

Más información sobre Netskope GovCloud
Netskope GovCloud
  • Recursos chevron

    Obtenga más información sobre cómo Netskope puede ayudarle a proteger su viaje hacia la nube.

  • Blog chevron

    Descubra cómo Netskope permite la transformación de la seguridad y las redes a través del perímetro de servicio de acceso seguro (SASE)

  • Eventos y Talleres chevron

    Manténgase a la vanguardia de las últimas tendencias de seguridad y conéctese con sus pares.

  • Seguridad definida chevron

    Todo lo que necesitas saber en nuestra enciclopedia de ciberseguridad.

Podcast Security Visionaries

Predicciones para 2025
En este episodio de Security Visionaries, nos acompaña Kiersten Todt, presidenta de Wondros y ex jefa de personal de la Agencia de Seguridad de Infraestructura y Ciberseguridad (CISA), para analizar las predicciones para 2025 y más allá.

Reproducir el pódcast Ver todos los podcasts
Predicciones para 2025
Últimos blogs

Lea cómo Netskope puede habilitar el viaje hacia Zero Trust y SASE a través de las capacidades de perímetro de servicio de acceso seguro (SASE).

Lea el blog
Amanecer y cielo nublado
SASE Week 2024 bajo demanda

Aprenda a navegar por los últimos avances en SASE y Zero Trust y explore cómo estos marcos se están adaptando para abordar los desafíos de ciberseguridad e infraestructura

Explorar sesiones
SASE Week 2024
¿Qué es SASE?

Infórmese sobre la futura convergencia de las herramientas de red y seguridad en el modelo de negocio actual de la nube.

Conozca el SASE
  • Empresa chevron

    Le ayudamos a mantenerse a la vanguardia de los desafíos de seguridad de la nube, los datos y la red.

  • Ofertas de Trabajo chevron

    Únase a los +3,000 increíbles miembros del equipo de Netskopeque construyen la plataforma de seguridad nativa en la nube líder en el sector.

  • Soluciones para clientes chevron

    Le apoyamos en cada paso del camino, garantizando su éxito con Netskope.

  • Formación y Acreditaciones chevron

    La formación de Netskope le ayudará a convertirse en un experto en seguridad en la nube.

Apoyar la sostenibilidad a través de la seguridad de los datos

Netskope se enorgullece de participar en Vision 2045: una iniciativa destinada a crear conciencia sobre el papel de la industria privada en la sostenibilidad.

Descubra más
Apoyando la sustentabilidad a través de la seguridad de los datos
Ayude a dar forma al futuro de la seguridad en la nube

At Netskope, founders and leaders work shoulder-to-shoulder with their colleagues, even the most renowned experts check their egos at the door, and the best ideas win.

Únete al equipo
Empleo en Netskope
Netskope dedicated service and support professionals will ensure you successful deploy and experience the full value of our platform.

Ir a Soluciones para clientes
Servicios profesionales de Netskope
Asegure su viaje de transformación digital y aproveche al máximo sus aplicaciones en la nube, web y privadas con la capacitación de Netskope.

Infórmese sobre Capacitaciones y Certificaciones
Grupo de jóvenes profesionales que trabajan

The Role of the Data Protection Officer in Europe

Oct 18 2017
Tags
CASB
Cloud Data Protection
Data privacy
GDPR

The EU General Data Protection Regulation (‘the Regulation’) means that the role of the Data Protection Officer will at long last be given a Pan-European legislative construct.

Current position

There are already many multinationals that have a Chief Privacy Officer or Chief Data Privacy Officer (‘DPO’) and whilst there are a number of EU Member States that specifically reference the role of the DPO there is no harmonised approach at present.

The adoption of new rules relating to Privacy Seals by the French Data Protection Authority (CNIL) stipulates a number of duties to be observed by the DPO and this article will look at examples of the roles and responsibilities of the DPO in Europe and likely additions to those roles once the Regulation comes into force.

Currently some European jurisdictions mandate or legislate for the appointment of the DPO for example Germany, France, Hungary, Slovenia, Russia and Poland.

Where a DPO is appointed they are empowered to ensure that the data controller is compliant with all aspects of applicable data protection laws and regulations, and in some jurisdictions the contact details of the DPO must be registered with the relevant data protection authority (‘DPA’).

In a number of jurisdictions the formal appointment of a DPO negates requirement for notification or registration of the data controller with the relevant DPA on the basis that it is the duty of the DPO to maintain a compliance register and to oversee the management of processing personal data that would have otherwise been covered by a notification or registration process.

DPO responsibilities

Currently one of the first responsibilities of the DPO is to manage notifications or registrations with the relevant data protection authority in respect of the data processing activities of the data controller. Furthermore the DPO must keep such notifications and registrations up-to-date and to maintain separate notifications in respect of all data processing entities within the corporate group.

There are particular obligations placed on DPO’s in respect of notifications and registrations in respect of processing sensitive personal data as well as the international transfer of personal data (and particularly sensitive personal data) and other processing activities such as whistleblower or ethical hotlines.

It must be remembered that in the EU the process of notification and registration is more than a “tick box” exercise and also more than a mere bureaucratic filing formality.

The notification or registration of the data controller with a DPA assists the DPA in its ability to enforce data protection compliance and the DPO needs to be fully informed of all processing activities in order to ensure that faster notifications and registrations are accurate and up-to-date.

In some European jurisdictions data processing cannot occur without prior registration of data processing activities and without prior approval of the relevant DPA. In addition specific notifications fall within the responsibility of the DPO where those notifications relate to whistleblower and ethical hotlines, international transfers of personal data (particularly of a sensitive nature) and notifications of data breaches for cyber incidents. Another general responsibility of the DPO is to monitor the activities of all data controllers within the DPO’s corporate group including HR, sales and marketing, IT, procurement and outsourcing.

The DPO needs to have in place a policy and procedure that ensures liaison with relevant departments in respect of any changes to processing activities – such as HR in relation to staff, leavers, job interviews and recruitment, background checks, new members of staff and the use of agents or sub-contractors.

The DPO is or should be a “C Suite” person who has direct reporting to the management in respect of data privacy and related compliance issues. The DPO shall have the autonomy and related budget and decision-making powers to manage non-compliance and related events including reporting of such incidents to the relevant DPA.

Implementing policies

The DPO needs to implement policies and procedures to manage the outsourcing of data processing activities including the use of third party vendors for HR, IT and marketing and particularly where those third party vendors may be processing personal data of the company outside the European Economic Area and/or within the Cloud.

The DPO needs to maintain close relationships with the Chief Information Security Officer (CISO) in order to manage not only the contractual issues and compliance issues relating to the processing of personal data but also the information security policies and procedures relating to that processing and cyber security planning.

In terms of the development of policies, procedures and practices the DPO needs to:

  • Provide guidelines to the Board of Directors as well as all members of staff;
  • Provide guidelines to joiners or new members of staff;
  • Provide guidelines to contractors and third parties that are using company facilities and company information;
  • Liaise with HR in relation to the development of policies, procedures and practices and for particularly members of staff, interviewees and job applicants;
  • Liaise with the IT department in relation to the development of policies, procedures and practices for information security, data handling, outsourcing, BYOD and monitoring in the work place; and
  • To liaise with sales and marketing to ensure compliance with applicable laws and regulations for marketing, advertising, profiling and publicity.

Another important aspect of the role of the DPO is that of training. Apart from the fact that training is an essential element of implementing compliance it is also in the eyes of the data protection authorities an intrinsic part of compliance with the law. There have been a number of instances where when an investigation has been carried out by a DPA, the lack of training on policies and procedures has increased the fines and/or settlement.

The DPO therefore must provide facilities for training in order to raise awareness of policies and procedures amongst existing staff, new staff and the Board. In addition the DPO needs to advise and coordinate in-house training tailored to specific departments and teams and produce regular information as changes in laws and regulations emerge. This is a significant role as the global privacy frameworks change almost daily and the DPO needs access to as much information and updates as possible from external sources in order to keep fully abreast of laws, regulations and regulatory guidance.

In many jurisdictions in Europe data subjects have the right to know from the data controller what personal information that data controller is processing about them. This right is often called a Subject Access Request (‘SAR’) and when a SAR is received by the data controller there is often a fixed mandatory period for the data controller to properly respond to the SAR and therefore the DPO needs to implement a SAR policy and procedure as well as internal training on how a SAR is to be properly managed. When an a data subject issues a SAR it is usually in circumstances where the individual is unhappy or concerned about personal data being processed by the data controller and the SAR policy needs to anticipate the complexity of responding to a SAR particularly where large volumes of personal information are processed by the data controller in respect of that individual whether they are an employee or a customer.

Many jurisdictions in Europe do not allow the data controller to charge for responding to a SAR and yet the cost of responding to a SAR can run to hundreds of hours particularly where the company does not have a robust records management system. The DPO needs to ensure that there is a records management policy that enables searches for personal records to be made in electronic databases as well as manual records since both are caught by the requirements of a SAR. This will mean understanding what personal information is held within the data controller’s network as well as on personal devices on members of staff or on manual files.

The SAR process means that attention also needs to be given to document retention and document destruction policies as well as homeworking and BYOD policies.

Finally under current legislation the Data Protection Officer is responsible for managing compliance audits. This is particularly the case where the DPO is an appointed officer and registered with the local data protection authority. In terms of audits not only do they need to be carried out regularly but there needs to be a procedure such as a Privacy Impact Assessment (‘PIA’) that addresses changes to policies, procedures and practices as a result of technology changes or company procedures.

From an ethical point of view when audits are carried out, the DPO should consider using a third party to audit specific policies created by the DPO.

author image
Robert Bond
Browse recent articles by Robert Bond, one of the contributors at Netskope. Discover the latest trends and updates within the cloud and network space.
Browse recent articles by Robert Bond, one of the contributors at Netskope. Discover the latest trends and updates within the cloud and network space.

Stay informed!

Suscríbase para recibir lo último del blog de Netskope