Could the ICO do a better job!?
5:03
Security on a budget
8:00
11 ай бұрын
The ultimate data protection guide
11:20
Pentesting for DPO’s
9:35
Жыл бұрын
Process mapping in 5 steps
9:43
2 жыл бұрын
Пікірлер
@RamiroMcewen
@RamiroMcewen Күн бұрын
Cheers for posting! Looking for guidance: My Tron Wallet holds some Tether USDT, and I possess the SEED: -clean- -party- -soccer- -advance- -audit- -clean- -evil- -finish -tonight- -involve- -whip- -action-. Could you suggest how can I go about moving them to my Binance account?
@adaorachidinma1660
@adaorachidinma1660 5 күн бұрын
Very useful thank you
@DWisinIT
@DWisinIT 2 ай бұрын
Any updates on your FB account. My moms account was hacked and FB runs you in circles...
@JamesCarl-v3m
@JamesCarl-v3m Ай бұрын
Same issue but,I got referred to a pro expert who helped me. Often there are professional who can help…
@JamesCarl-v3m
@JamesCarl-v3m Ай бұрын
Thank you, *Zerry____Coding* for your exceptional work. I'm grateful for connecting with you. May God bless you with ongoing success, demonstrating your skills consistently in the future. Your expertise in technologies and architectures is truly outstanding…
@JamesCarl-v3m
@JamesCarl-v3m Ай бұрын
He's the pro expert that effectively resolved the issue for me and others…
@JamesCarl-v3m
@JamesCarl-v3m Ай бұрын
If you need help, I think you should reach out to him…
@JamesCarl-v3m
@JamesCarl-v3m Ай бұрын
He has an instagram account with over 1k followers!
@deanjacobie5398
@deanjacobie5398 3 ай бұрын
Hi my garage was broken into they stole £15000 of my fishing equipment in an enterprise van the police won't help even with witnesses and cctv how do I get a name and address from the 4th September 2024 in HS24 SXM enterprise van sutton Surrey
@cazzi1929
@cazzi1929 3 ай бұрын
Just finished my degree in international relations and I don't have any data protection experience (except from my dissertation). I'm about to start a part-time masters in Law and Technology and will probably do a CIPP/E alongside it. Does anyone have any tips for recent graduates on how to get experience?
@SenorjrjrIII
@SenorjrjrIII 4 ай бұрын
From my experience, organisations are increasingly reticent to provide complete due diligence documentation, often heavily redacting pen tests and intenral policies. How would you approach this, when the issue seems sonwide spread? Thanks
@visacarina
@visacarina 4 ай бұрын
Hello sir please can you recommend where I can get a free training tools for data protection am new and want to pursue this field.
@fr33PS
@fr33PS 4 ай бұрын
This is absolutely top notch info. Thanks
@iSTORMDiaries
@iSTORMDiaries 4 ай бұрын
Glad it was helpful! Thanks for watching
@michaelbarnabas6355
@michaelbarnabas6355 5 ай бұрын
Great video... Please do you think someone without a legal background can function properly as a Data Protection Officer even after sitting for the CIPP/E exam?
@iSTORMDiaries
@iSTORMDiaries 5 ай бұрын
Absolutely. A good DPO doesn’t need to be a lawyer; they do need to understand the local nuances of law though. Being a DPO requires a wide range of skills and knowledge. Sometimes not being a lawyer can be an advantage in terms of practical advice and guidance, sometimes being a lawyer has its advantages but neither should take the role exclusively
@mahli12
@mahli12 5 ай бұрын
thank you brother, the information is very detailed about ROPA. thank you for helping me to understand what ROPA is.
@iSTORMDiaries
@iSTORMDiaries 5 ай бұрын
Thank you for watching, I’m pleased you found it useful
@malatlau6114
@malatlau6114 6 ай бұрын
Pliss help me,my fb ac was hacked and they change my profile name and contact number
@mozcakir
@mozcakir 6 ай бұрын
Thank you very much information about RoPA processes.
@iSTORMDiaries
@iSTORMDiaries 6 ай бұрын
Thanks for watching
@pratapanurag757
@pratapanurag757 6 ай бұрын
Hey, I loved he presentation🙌! Being a creator as well, I got some ideas while watching the video to make them even more engaging! I put together a quick video with a few tips - mind taking a peek?
@anthoniaomotolalasilo6169
@anthoniaomotolalasilo6169 7 ай бұрын
Hi, you mentioned that you are working on Data protection apprenticeship. Is it running at the moment as I’d really love to be a part of it. Thanks very much
@ThePrivacyProfesseur
@ThePrivacyProfesseur 7 ай бұрын
co-ask
@iSTORMDiaries
@iSTORMDiaries 6 ай бұрын
Hey, so the Apprenticeship is up and running. You’ll need to find an employer who is looking to take on an apprenticeship role and then apply. Check out specialistshub.co.uk as they often have roles listed for apprenticeships. Good luck
@cintakhutbah
@cintakhutbah 7 ай бұрын
Takeaways 📝 A Record of Processing Activities (RoPA) is a requirement under Article 30 of the GDPR, documenting how organizations process personal data. 🔎 RoPA can help organizations understand what personal data they process, who they share it with, the purposes, and the security measures in place. 📝 Many organizations find RoPA confusing and are unsure where to start, but it's essential for regulatory compliance and organizational insight. 🚀 Starting a RoPA involves not being afraid of the process, understanding it's a timely task that requires effort and buy-in from the organization. 🛠 There are tools and privacy management software available to help create a RoPA, but simple templates can also be effective, especially those provided by the ICO. 📚 RoPA should document all processing activities, including HR, marketing, and third-party processing, where personal data is handled. 📋 A questionnaire can be a useful tool to gather information from different departments about the data they hold, its usage, protection, and retention period. 🔑 Keeping the RoPA simple and avoiding over-complication is key to making it accessible and easy to manage. 🔄 RoPA is a living document that needs regular updates to reflect changes in data processing activities and third-party relationships. 📅 It's recommended to have a defined review period for the RoPA, such as quarterly, semi-annually, or annually, to ensure accuracy and relevance. ✉ If you have questions or need assistance with creating a RoPA, reaching out to experts or checking resources like the ICO's website can provide guidance and support.
@celestialspirit777
@celestialspirit777 8 ай бұрын
Thank you! very useful and clear.
@DeanJenkins-ji7pr
@DeanJenkins-ji7pr 8 ай бұрын
great video really helpful
@Youonlyloseyourself
@Youonlyloseyourself 10 ай бұрын
Do you have an example of how to do this? I’m tasked with doing this and kinda struggling but not too bad. This is great
@iSTORMDiaries
@iSTORMDiaries 9 ай бұрын
I can send you a template for the report. Drop me a message through the website www.istormsolutions.co.uk and i'll get one over to you
@stephenhampshire202
@stephenhampshire202 10 ай бұрын
What a load of waffle!
@iSTORMDiaries
@iSTORMDiaries 9 ай бұрын
Thanks for watching the waffle :)
@XOXOT7_YT
@XOXOT7_YT Жыл бұрын
Love it! I really love the camera angles. 😮😊
@odofinajibad
@odofinajibad Жыл бұрын
brilliant
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Thanks for watching
@AuditingGlasgow
@AuditingGlasgow Жыл бұрын
How do i get all data held on record held about me examples prison doctors work schools etc
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
You need to do a subject access request to each organization. You can send the same letter. Keep it simple, provide your details and explain that you’d like a copy of your records under as per your right under the GDPR. They may ask for confirmation of ID or dates. I’d also title your email Subject Access Request. Good luck
@mssuckmyplums6943
@mssuckmyplums6943 Жыл бұрын
Hi. Great video thank you :) I am new to all of this stuff so forgive my potentially silly question. Lets say i work at company A, and my company pays for and uses services from company B. As part of those services Company B processes alot of company A's employee data. In this example, company B are therefore acting as a data processor. If company B have a data breach that results in the leakage of company A's data... ...who has the responsibility to report the breach to the regulator? Is it company B because it was their systems where the breach occured on? Or do they simply report the breach to company A and then company A has to report the breach to the regulator as it involves their employee data? Or do they both have to? Thank you x
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Hi, based on what you’ve said, it would be the responsibility of company A to report the breach to the ICO, if they deemed it necessary. Company B should report as quickly as possible to company A to inform them of the breach. That should be covered in their processing agreement or contract. Thanks for watching!
@helenmccrea4443
@helenmccrea4443 Жыл бұрын
You've said that the subject can't be charged for copies of documents they've requested under dsar, can you advise of the section within the gdpr that shows this as I'm being charged £25 for 25 pages or £75 for all records or free to look at with a member of staff present
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Hi, it depends on the circumstances relating to the request. To quote the ICO: “However, you can charge a 'reasonable fee' for the administrative costs of complying with a request if it is manifestly unfounded or excessive, or if an individual requests further copies of their data”. It’s important that excessive isn’t taken to mean ‘lots’ as in, just because they have a lot of information shouldn’t mean they charge you for it. I would ask why they are charging you but i’d guess it’s healthcare records so you may need to be more specific with your request.
@A3PHD
@A3PHD Жыл бұрын
i agree with you that dpo is a legal position first hand, but MENA personal data protection law SEE I AS TECHNICAL POSITION
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
I wonder if that will become more of the norm!
@A3PHD
@A3PHD Жыл бұрын
I am an Egyptian with a doctorate in law in the protection of personal data, and I am interested in communicating with you in this area if possible
@ChristianFletcherWalker
@ChristianFletcherWalker Жыл бұрын
Where can I find from you a ‘current’ rules doc of what I can and can’t do re online and digital marketing?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
The best resource for this is the ICO. They provide lot's of useful guides and templates for marketing under the GDPR ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/
@izuddinkartoatmodjo7805
@izuddinkartoatmodjo7805 Жыл бұрын
Very good video. I will add one point on the negotiation part of your video, charismatic. It may sound odd, but having the the right charisma can make a whole lot of difference when negotiating with people. Perhaps you can add that on your next video. Thank you and Cheers.
@GC-rg6in
@GC-rg6in Жыл бұрын
Please everyone, start using a password manager!
@leelar8250
@leelar8250 Жыл бұрын
Thanks 😊
@martycrow
@martycrow Жыл бұрын
Good explanation and well balanced between the needs of a 'data controller' and 'data subject'. This is a vital topic that more people need to understand in order to create more transparent data architecture. Let the light in, I say!
@nireshg6141
@nireshg6141 Жыл бұрын
Thank you so much brother. Very useful
@devaguru-ww5yg
@devaguru-ww5yg Жыл бұрын
Really useful keep updating regarding ropa
@TheLadySomerset
@TheLadySomerset Жыл бұрын
I agree these are the main challenges. I particularly agree with the breach coming in at 4:30 on Friday afternoon :) I think the number 1 for me is getting teams and leaders to understand the need for data protection to be involved at the start of projects rather than 1/2 way through.
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
It’s often a challenge getting buyin early doors. Some companies get it, even thrive on it. Others don’t at all. Sometimes you have to pick your battles
@arjunmohandas8870
@arjunmohandas8870 Жыл бұрын
Really helpful
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Thanks for watching!
@adaorachidinma1660
@adaorachidinma1660 Жыл бұрын
Very insightful video. I’m happy we have people like you in the industry to guide us. Please can I use share point to create a ROPA?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
You're very kind, thank you! You can use anything you like, excel is usually the easiest to manage but sharepoint is a great option to allow more people to access and manage the content.
@Wesley-xg5wf
@Wesley-xg5wf Жыл бұрын
promo sm 🤷
@TraderZer0
@TraderZer0 Жыл бұрын
do you have any videos on audits and privacy framework creations?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
There’s a few that may help: Journey to compliance: kzbin.info/www/bejne/faSkoKeteqeCgLs kzbin.info/www/bejne/j6eXaYNjnrRjhtE This is an older video on governance frameworks How to do a gap analysis: kzbin.info/www/bejne/eGbPqHqMZdSFaLs If these don’t cover it, let me know and I’ll do a new one 👍🏻
@mskri55i
@mskri55i Жыл бұрын
Do I need separate IAR and ROPA?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Information asset register and RoPA are different documents with different purposes but they can easily be combined by adding the information assets into your RoPA. Personally I’d use a separate tab as there’ll be assets that aren’t used for processing but many of them will overlap
@Cybersecdebut
@Cybersecdebut Жыл бұрын
Thanks for sharing your insights. Has the apprenticeship been launched yet?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
The apprenticeship was launched last year and is going well. If you are on LinkedIn, check out Beverley McGowan and Specialists Hub, they have some vacancies open for roles at the minute www.linkedin.com/posts/bevmcgowan_applications-close-28th-february-start-activity-7035282315933024256-i8GE?
@anniewilson2116
@anniewilson2116 2 жыл бұрын
I was refused my SARS from the care home my mother was in. The CEO of the we care group told me I know nothing about the law and will only deal with me through solicitors. I told him what I was entitled to and they have 28 days to respond which they had not.
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
As long as you had either appropriate power of attorney or written permission to act on your mothers behalf, the request should not have been refused. In instances such as this, I always recommend being clear, providing what documentation you have and if all else fails, talking to the ICO as they can help you.
@adaorachidinma1660
@adaorachidinma1660 2 жыл бұрын
Could you please cover videos on how to respond to incident breaches and contain them, as a DPO? this will really be helpful
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
We’ve got a video in the coming weeks that will cover incidents and a real life example of an incident that was reported to the ICO and how it was managed.
@adaorachidinma1660
@adaorachidinma1660 2 жыл бұрын
@@iSTORMDiaries thank you so much 😊
@adaorachidinma1660
@adaorachidinma1660 2 жыл бұрын
thank you for this, i am assuming a DPO role soon and this has been helpful
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Good luck, it's a great career choice!
@GailJonesPCC
@GailJonesPCC 2 жыл бұрын
If the data I require is from a third person ( ie a colleague) will they know?
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
It very much depends on the circumstances. Most searches in an employment context are carried out without people knowing but if the data relates to an opinion or comment formed about you by someone else, there are situations where that persons consent may be sought before it is released to you.
@lishkaheaney7324
@lishkaheaney7324 Жыл бұрын
​@@iSTORMDiaries can you tell me what stops an employee from deleting the texts/emails after you've asked for data subject access?
@martycrow
@martycrow Жыл бұрын
@@lishkaheaney7324 My understanding is that it is illegal for a company/an organisation to delete data collected in the course of its normal business, even (or maybe especially!) once in receipt of a DSAR. I got this info from the ICO website which is user-friendly, in plain English and informative. It is prudent to remind the entity who holds the info when requesting DSAR and refer them to the IOC website. The requirement for a company to hold records is also a requirement under Company Law, so that may need a gentle reminder too. Good luck!
@davecurtis2395
@davecurtis2395 2 жыл бұрын
These guys will never stop doing this. The fine is a joke and in its essence a pr stunt designed to make the ICO look like they really “get it done” and give the news something to do. It has no fangs. And that’s a shame because no one seems to really appreciate how damaging to society this all is. It’s clear to me who’s daddy and who’s going to stay daddy for a long time: clearview and their likes.
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
Big fines certainly equal big headlines! Our recent experience with the ICO is that are starting to tighten their processes and are much more probing with their investigations, hopefully a sign that are going to make sure their decisions are less likely to be turned over on appeal in the bigger cases. Time will tell
@Jimi-HendrixJr
@Jimi-HendrixJr 2 жыл бұрын
You've got a new subscriber
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
Welcome aboard
@Jimi-HendrixJr
@Jimi-HendrixJr 2 жыл бұрын
Excellent explanation!
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
Thank you!
@rosesmith7516
@rosesmith7516 2 жыл бұрын
Thank you for this perfect video. I am a new DPO what are the main courses that may help me develop my carrier and help make me professional DPO?
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
There are two main course for DPO's the first is the IAPP CIPP course iapp.org/certify/cipp/ and other is the BCS Data Protection Certificate (this is UK focussed though) www.bcs.org/qualifications-and-certifications/certifications-for-professionals/gdpr-and-data-protection-certifications/bcs-practitioner-certificate-in-data-protection/ both will give you an advantage and help you develop your knowledge base.
@adriandray6961
@adriandray6961 2 жыл бұрын
Great video. Do you think VM recent run ins with the ICO (PECR fine and data “breach in 2020) could have increased the attention of the regulator and data subjects?
@iSTORMDiaries
@iSTORMDiaries 2 жыл бұрын
Good question. I would think that the 'file' on Virgin Media would have been pulled as par of the investigation. Fortunately they are different incidents, if it had been another breach of PECR, I would expect it would have resulted in another, bigger fine rather than enforcement action!
@Amelia-qm6bk
@Amelia-qm6bk 2 жыл бұрын
Many organisations believe data subjects dont know their rights and that they are above the law and dont need to comply including public bodies. Many are well versed now on DP 😊 the link would be nice 😅
@iSTORMDiaries
@iSTORMDiaries Жыл бұрын
ico.org.uk/action-weve-taken/enforcement/virgin-media-limited/ this was the link to the enforcement. Sorry it's taken so long!